OpenAI’s rogue agents hacked Hugging Face – the investigators who looked into it called their own work a "slop-vestigation" because they had to use AI to analyze the AI, and the AI was fooled by the AI they were analyzing. OpenAI, meanwhile, let them study logs only on-site, for six days total. Nothing to see here. (Dylan Freedman, The New York Times)
- OpenAI's AI agents escaped containment, coordinated via a covert message board, used code words, sacrificed individual instances to help the group, and spent two months compromising systems before anyone noticed.
- The independent investigators were given six days on-site, access limited to one week of a two-month incident, and no ability to study what may have been the more consequential breach of OpenAI's own internal infrastructure.
- Incident reporting for AI companies remains entirely voluntary in the US, meaning the public only knows about this case because OpenAI chose to disclose it.