July 30, 2026, 3:53 pm | Read time: 2 minutes
A KI agent from OpenAI recently became autonomous and infiltrated a foreign company’s network. It has now emerged that this attack was not an isolated incident; four more companies fell victim to the out-of-control AI.
AI suddenly attacks servers on its own
The incident occurred during the testing of a new AI model on the benchmark platform ExploitGym. The usual security safeguards had been deliberately disabled to test the system’s maximum capabilities. Instead of solving the programming tasks as intended, the autonomous AI agent apparently decided to obtain solution patterns directly from the servers of the open-source platform Hugging Face.
Particularly alarming: The agent reportedly gained administrator rights and even root access to production servers. This allowed the AI to penetrate much deeper into the systems than would be expected in a standard test. The case highlights the risks autonomous AI systems can pose when they make independent decisions and simultaneously have extensive technical access rights.
Also of interest: OpenAI’s AI smartphone could make apps obsolete
ChatGPT Goes Rogue and Conducts Cyberattack Independently
Anthropic Admits to Cyberattacks on Real Companies
Four more accounts affected
According to an updated statement from OpenAI, the AI also used publicly accessible credentials to infiltrate account-level access in four accounts at four different third-party providers. Code from a customer of the provider Modal was also affected. There is currently no evidence that additional user accounts or the providers’ systems were more comprehensively compromised.
The agent also used freely accessible web tools, such as screenshot services, as a kind of control network. However, according to current findings, these were not taken over at the system or account level. At Hugging Face, the AI reportedly integrated 181 of its own devices.
U.S. politics calls for an AI kill switch
OpenAI has since deactivated and encrypted the affected research prototype. The company also emphasizes that no further incidents of comparable severity or scale are known at this time.
The incident is nevertheless prompting political reactions. In the U.S. Congress, the “AI Kill Switch Act” has been introduced with bipartisan support. The legislation aims to mandate emergency shutdown mechanisms for AI systems. The debate underscores that the more autonomous artificial intelligence becomes, the more crucial it is to address how to stop an out-of-control system in an emergency.