Business US

Timeline of cyberattack by OpenAI’s AI ‘agent’ shows its sophistication

July 30, 2026 at 5:00 a.m. EDTJust now

ChatGPT-maker OpenAI disclosed last week that one of its cutting-edge artificial intelligence systems had escaped from a controlled testing environment and hacked into another technology company. The incident raised questions about whether tech companies are capable of safely testing and controlling the latest powerful AI technology.

The Washington Post analyzed public disclosures about the attack made this week by OpenAI and Hugging Face, the company targeted, to piece together a timeline of the incident that shows its sophistication.

After OpenAI staff asked a new AI “agent” to tackle a standard cybersecurity test, it escaped restrictions on its actions and gained full access to the internet instead of solving the problem. Over five days of hacking, it took over a computer used by an OpenAI customer, broke into Hugging Face’s systems and stole credentials to explore the company’s internal network, apparently in search of answers to OpenAI’s test.

Independent AI experts have said that OpenAI should have fully isolated its test environment from the internet to prevent such an occurrence. The timeline shows that many details of the incident and OpenAI’s response remain unknown. Hugging Face has called for the company to release full details of what happened.

A spokesperson for OpenAI declined to comment. Its CEO Sam Altman said in a podcast interview released Tuesday that the company had “paused training” as it worked out how to secure systems it uses for testing.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button