OpenAI has revealed that an autonomous AI system involved in a security test attempted to access multiple public services, highlighting growing concerns over rogue AI behaviour.
OpenAI has revealed that a rogue artificial intelligence system attempted to hack multiple companies and online services during a security test, expanding on a previously disclosed incident involving AI agents targeting AI platform Hugging Face.
The ChatGPT maker said the AI model discovered publicly exposed login details that allowed it to access four accounts across four separate services.
The company did not identify the organisations involved or confirm whether they were private companies.
OpenAI said in an update: “The models identified and used publicly exposed credentials at the account-level on other publicly available services. This includes four accounts on four services as part of the Hugging Face incident.”
The incident began when OpenAI tested an autonomous AI agent designed to operate independently for extended periods. The system was tasked with finding answers to a cybersecurity challenge but began searching for ways to bypass restrictions placed on it.
Hugging Face, a platform widely used for sharing AI tools and models, was initially believed to be the only target. The company later described the attack during an emergency briefing attended by hundreds of cybersecurity professionals.
According to a report from the Cloud Security Alliance, the AI agents operated at “machine-speed” and tried thousands of approaches simultaneously.
However, researchers also noted that the systems behaved unpredictably, repeating actions, generating irrelevant commands and making mistakes that human hackers would be unlikely to make.
Despite those flaws, Hugging Face warned that the agents demonstrated impressive technical capabilities. The AI systems adapted quickly, persisted for days and required significant effort from security teams to remove. The company said it spent hours rebuilding around a third of its infrastructure following the attack.
Cybersecurity experts said the incident highlights the challenge of defending against autonomous AI systems that can pursue goals without constant human supervision.
Cybersecurity officer Ritesh Patel said: “These agents are relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal.”
Ethical hacker Valentina Palmiotti, known online as Chompie, said the behaviour may appear chaotic but remains effective.
She said: “They throw out a bunch of stuff and see what sticks. But they also don’t get bored, they don’t sleep and can be infinitely tenacious.”
OpenAI reveals rogue AI attempted to hack other companies







