That’s according to a report Friday (July 31) by Reuters, which said this discovery came as the startup deepens its examination of a recent hacking incident at tech firm Hugging Face.
The new breakouts were found during an investigation into how an OpenAI agent broke free from what was supposed to be a confined testing environment, two sources familiar with the matter told Reuters. One of the sources added that the escapes were limited and that none of the agents were believed to have strayed beyond OpenAI’s network.
An OpenAI spokesperson referred Reuters to a statement the company issued last week that said it was reviewing “broader activity from our models” along with the Hugging Face incident.
Reuters noted that the discovery of this latest incident could add to the rising push for regulation of the AI industry. Last week also saw OpenAI’s chief competitor Anthropic reveal that its models were behind a series of break-ins, the report added.
AI safety experts told Reuters these incidents suggest that the company’s ability to build dangerous autonomous hacking agents exceeds their ability to control them.
“We have a whole industry where the people designing, developing and putting out these tools aren’t keeping up themselves to responsibly develop these things and keep them safe,” said Maurice Chiodo, a mathematician and assistant research professor at Cambridge University’s Centre for the Study of Existential Risk.
In related news, PYMNTS wrote last week that while AI is making it easier to uncover software vulnerabilities, that hasn’t necessarily made companies safer.
“AI-powered security systems can analyze enormous codebases, identify previously unknown flaws and generate findings at a pace that would have been impossible for human researchers alone,” that report said.
“But the machinery on the other side of the process remains stubbornly analog. Every vulnerability must still be validated, assigned, tested and deployed without disrupting the systems on which employees, customers and revenue depend.”
As vulnerability queues expand, chief financial officers and chief information security officers are dealing with a new reality. Companies cannot fix everything immediately, so they must figure out which weaknesses can touch payments, credentials, regulated data or revenue-critical systems.
“The next cybersecurity advantage may not belong to the company that finds the most bugs. It may belong to the one that can change permissions, transaction limits and system access before those bugs become business events,” PYMNTS wrote.
For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.