{"id":3046,"date":"2026-07-29T14:55:49","date_gmt":"2026-07-29T14:55:49","guid":{"rendered":"https:\/\/arabnewsmonitor.com\/2026\/07\/29\/openai-escape-has-the-robot-uprising-begun\/"},"modified":"2026-07-29T14:55:49","modified_gmt":"2026-07-29T14:55:49","slug":"openai-escape-has-the-robot-uprising-begun","status":"publish","type":"post","link":"https:\/\/www.arabnewsmonitor.com\/?p=3046","title":{"rendered":"OpenAI escape: has the robot uprising begun?"},"content":{"rendered":"<p><strong>Sam Altman\u2019s company claims that its most powerful model can execute complex hacking operations on its own<\/strong><\/p>\n<p>A cutting-edge AI model developed by OpenAI has managed to escape the confines of a lab test and break into a company\u2019s database without any human instruction. It\u2019s a nightmare scenario \u2013 or is that just what OpenAI wants you to believe?<\/p>\n<blockquote><p>\n        <span><strong>Read more<\/strong><\/span><\/p>\n<figure>\n            <img decoding=\"async\" src=\"https:\/\/mf.b37mrtl.ru\/files\/2026.07\/thumbnail\/6a5973d985f5400ca946b675.jpg\" alt=\"Representatives of 29 nations at the World Artificial Intelligence Cooperation Organization in Shanghai, China, July 16, 2026.\"><figcaption><a href=\"https:\/\/www.rt.com\/news\/643156-russia-china-ai-waico\/\">Russia and China seek to define global AI principles<\/a><\/figcaption><\/figure>\n<\/blockquote>\n<p>On July 16, OpenAI carried out an internal benchmark test on GPT\u20115.6 Sol and another pre-release model that the company claims is <em>\u201ceven more capable.\u201d<\/em> The models had their guardrails disabled and were put to work solving a series of cybersecurity tests known as ExploitGym. Developed by researchers at UC Berkeley, Germany\u2019s Max Planck Institute, and AI companies including Google, Anthropic, and OpenAI itself, ExploitGym measures AI models\u2019 ability to create and deploy the means of exploiting known security vulnerabilities.<\/p>\n<p>Instead of identifying these vulnerabilities, OpenAI\u2019s models searched for ways to cheat the test. They managed to obtain open internet access from within the closed testing environment and used this newfound freedom to hack into Hugging Face\u2019s servers. Hugging Face is a repository of AI models and datasets, and according to OpenAI, the models being tested reasoned that they could find a solution to the ExploitGym tasks there.<\/p>\n<p><em>\u201cKnowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation,\u201d<\/em> OpenAI said in its report about the incident.\u00a0<\/p>\n<p>Hugging Face discovered the intrusion with the help of a different AI model, and fixed the vulnerability that allowed it to happen in the first place. On its end, OpenAI blamed the escape on a weakness in third-party software used in its testing lab, through which its models found internet access. It kept the technical details of how its models exploited this weakness under wraps.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Super impressed with <a href=\"https:\/\/x.com\/huggingface?ref_src=twsrc%5Etfw\">@huggingface<\/a>&#8216;s breakdown of the AI agent autonomous cyber attack from OpenAI, including technical timeline, &amp; interactive replay (AND how they defended against the attack)!<br \/>Here is the interactive attack replay vid and source:<a href=\"https:\/\/t.co\/SVsc5ClRcW\">https:\/\/t.co\/SVsc5ClRcW<\/a> <a href=\"https:\/\/t.co\/r59n6aUr3c\">pic.twitter.com\/r59n6aUr3c<\/a><\/p>\n<p>\u2014 Rachel Tobac (@RachelTobac) <a href=\"https:\/\/x.com\/RachelTobac\/status\/2082214795072225786?ref_src=twsrc%5Etfw\">July 28, 2026<\/a><\/p><\/blockquote>\n<p>On its path to breach Hugging Face\u2019s servers, the model also broke into a supposedly isolated testing environment at Modal, a firm that rents out computing capacity to AI developers, Reuters reported on July 28.<\/p>\n<h2>Has AI become sentient?<\/h2>\n<p>Taken at face value, the story suggests that OpenAI\u2019s models are capable of complex lateral thinking: suspecting that Hugging Face\u2019s servers likely contained the answers to the test; realizing that they needed external internet access to breach these servers; and independently developing and combining various attack techniques to achieve its goal.<\/p>\n<blockquote><p>\n        <span><strong>Read more<\/strong><\/span><\/p>\n<figure>\n            <img decoding=\"async\" src=\"https:\/\/mf.b37mrtl.ru\/files\/2026.07\/thumbnail\/6a4e0b0985f54032a9335e67.png\" alt=\"This image was generated using AI technology.\"><figcaption><a href=\"https:\/\/www.rt.com\/news\/642687-claude-ai-thinking-space-anthropic\/\">Claude AI evolved its own human-like thinking space \u2013 Anthropic<\/a><\/figcaption><\/figure>\n<\/blockquote>\n<p>OpenAI\u2019s statement described the escape in alarmist language, calling it an <em>\u201cunprecedented cyber incident, involving state-of-the-art cyber capabilities.\u201d<\/em> Hugging Face, which has since partnered with OpenAI, was equally hyperbolic. <em>\u201cAutonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed,\u201d<\/em> it said in a statement.\u00a0<\/p>\n<p>However, it remains unclear just how autonomously OpenAI\u2019s models were operating. The company has not revealed how its models were prompted to approach the ExploitGym test, and imprecise wording could have resulted in the models assuming that \u2018escaping\u2019 containment was a legitimate path to solving the trial. Despite the hyperbole from both OpenAI and Hugging Face, there is no evidence to suggest that the AI models \u2018wanted\u2019 to escape, or that when left to their own devices, would default to malicious activity.<\/p>\n<p>If the incident also involved \u2013 as OpenAI said it did \u2013 a second, <em>\u201ceven more capable pre-release model,\u201d<\/em> the appeal to industry-level customers is obvious. By publicizing an incident that took place during closed testing, OpenAI can generate hype for its pre-release model without ever providing proof.<\/p>\n<p>None of this is to say that the incident didn\u2019t happen, or that the offensive capabilities of AI aren\u2019t a cause for concern, just that OpenAI has a financial incentive to scaremonger about its own products. A month before the incident, the company confidentially filed the paperwork for an initial public offering. According to Reuters, the company is targeting a valuation of up to $1 trillion, and planning to go public as early as September.<\/p>\n<p>Anthropic also filed for its IPO in June, targeting a valuation of $965 billion in October. Back in April, Anthropic\u2019s unreleased Mythos Preview model also managed to <em>\u201cescape\u201d<\/em> its testing environment and carry out advanced cybersecurity exploits without being <em>\u201cexplicitly trained\u201d<\/em> to do so. Anthropic released a lengthy technical explanation of how Mythos pulled off this feat, before announcing that the model was too powerful to release to the public.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">The biggest IPO run in the history of the market<\/p>\n<p>three $1T+ companies. possibly all going public in the next 12 months.<\/p>\n<p>SpaceX IPO: $1.75T. <br \/>OpenAI IPO: $1T<br \/>Anthropic IPO: $1T<\/p>\n<p>we&#8217;re living through the greatest technological wealth creation in history. <a href=\"https:\/\/t.co\/44QuB3rpxi\">pic.twitter.com\/44QuB3rpxi<\/a><\/p>\n<p>\u2014 shirish (@shiri_shh) <a href=\"https:\/\/x.com\/shiri_shh\/status\/2049040515107270751?ref_src=twsrc%5Etfw\">April 28, 2026<\/a><\/p><\/blockquote>\n<p>Scarcity drives hype, and the US government\u2019s decision to slap export controls on Anthropic\u2019s Fable 5 and Mythos 5 models in June only heightened interest in the company. The export controls were lifted in early July after Anthropic agreed to impose stricter guardrails on its models and collaborate with the government on security.<\/p>\n<h2>Was the AI escape an elaborate marketing ploy?<\/h2>\n<p>For OpenAI, the incident is the best possible advertisement for its models\u2019 capabilities. In its report, the company included a graph illustrating how leading AI models \u2013 including GPT\u20115.6 Sol, Anthropic\u2019s Claude Mythos 5, and DeepSeek-V4-Pro \u2013 are <em>\u201cincreasingly able to sustain complex, multi-step cyber operations over long time horizons.\u201d<\/em> Although this is presented as a cause for concern, the chart lists GPT-5.6 Sol as the most capable among all of its competitors \u2013 a clear advertisement for OpenAI.<\/p>\n<blockquote class=\"twitter-tweet\" data-media-max-width=\"560\">\n<p lang=\"en\" dir=\"ltr\">Sam on the Hugging Face incident:<\/p>\n<p>\u201cThis is the first security incident that I have felt very viscerally. I&#8217;ve been a little surprised that more people don&#8217;t feel it so viscerally.<\/p>\n<p>We paused training. We have to figure out how to secure our sandboxing in a world of multiple zero\u2026 <a href=\"https:\/\/t.co\/XXeB7RZsM3\">https:\/\/t.co\/XXeB7RZsM3<\/a> <a href=\"https:\/\/t.co\/F4hbHuItqw\">pic.twitter.com\/F4hbHuItqw<\/a><\/p>\n<p>\u2014 Patrick OShaughnessy (@patrick_oshag) <a href=\"https:\/\/x.com\/patrick_oshag\/status\/2082090998990270885?ref_src=twsrc%5Etfw\">July 28, 2026<\/a><\/p><\/blockquote>\n<p>If the incident also involved \u2013 as OpenAI said it did \u2013 a second, <em>\u201ceven more capable pre-release model,\u201d<\/em> the appeal to industry-level customers is obvious. By publicizing an incident that took place during closed testing, OpenAI can generate hype for its pre-release model without ever providing proof. <\/p>\n<p>None of this is to say that the incident didn\u2019t happen, or that the offensive capabilities of AI aren\u2019t a cause for concern, just that OpenAI has a financial incentive to scaremonger about its own products. A month before the incident, the company confidentially filed the paperwork for an initial public offering. According to Reuters, the company is targeting a valuation of up to $1 trillion, and planning to go public as early as September.<\/p>\n<blockquote><p>\n        <span><strong>Read more<\/strong><\/span><\/p>\n<figure>\n            <img decoding=\"async\" src=\"https:\/\/mf.b37mrtl.ru\/files\/2026.02\/thumbnail\/698e81db85f540092a36736a.jpg\" alt=\"Anthropic Co-Founder &amp; CEO Dario Amodei.\"><figcaption><a href=\"https:\/\/www.rt.com\/news\/632390-anthropic-openai-political-rivalry\/\">Anthropic pours $20 mn into \u2018safeguards\u2019 clash with OpenAI<\/a><\/figcaption><\/figure>\n<\/blockquote>\n<p>Anthropic also filed for its IPO in June, targeting a valuation of $965 billion in October. Back in April, Anthropic\u2019s unreleased Mythos Preview model also managed to <em>\u201cescape\u201d<\/em> its testing environment and carry out advanced cybersecurity exploits without being <em>\u201cexplicitly trained\u201d<\/em> to do so. Anthropic released a lengthy technical explanation of how Mythos pulled off this feat, before announcing that the model was too powerful to release to the public.<\/p>\n<p>Scarcity drives hype, and the US government\u2019s decision to slap export controls on Anthropic\u2019s Fable 5 and Mythos 5 models in June only heightened interest in the company. The export controls were lifted in early July after Anthropic agreed to impose stricter guardrails on its models and collaborate with the government on security.<\/p>\n<h2>How has the US government responded?<\/h2>\n<p>Both incidents have caught the eye of lawmakers on Capitol Hill. On July 23, Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, which would <em>\u201crequire developers of the most powerful AI systems to maintain the technical capability to throttle, suspend, or shut them down.\u201d<\/em> The bill would also empower the US Department of Homeland Security to <em>\u201corder a slow down or shutdown of an AI system that can cause catastrophic harm.\u201d<\/em><\/p>\n<p>In a statement on the bill, Lieu referenced the \u2018escapes\u2019 of both of OpenAI\u2019s models, and of Mythos. The California lawmaker described both cases as models <em>\u201cgoing rogue,\u201d<\/em> a framing that the mainstream media picked up and ran with.<\/p>\n<p>Lieu knows no more about the OpenAI incident than anyone who\u2019s read the company\u2019s press release. However, his wording plays right into OpenAI\u2019s (perhaps unintentional) marketing campaign. Furthermore, should the bill pass, OpenAI and Anthropic could be forced to throttle their models before release, meaning investors will only ever know of their theoretical \u2013 and not their real-life \u2013 power.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">While powerful AI systems have many potential benefits, they can also go rogue, behave in extremely dangerous ways, or even resist human intervention.<\/p>\n<p>We need to keep human control by ensuring AI systems can be completely shut down if necessary. <a href=\"https:\/\/t.co\/y4JfaD8RFJ\">pic.twitter.com\/y4JfaD8RFJ<\/a><\/p>\n<p>\u2014 Rep. Ted Lieu (@RepTedLieu) <a href=\"https:\/\/x.com\/RepTedLieu\/status\/2080293165169357070?ref_src=twsrc%5Etfw\">July 23, 2026<\/a><\/p><\/blockquote>\n<h2>The open-source argument<\/h2>\n<p>The incident bolsters OpenAI\u2019s argument that frontier AI models are too powerful to be released to the public, and that companies like OpenAI should \u2013 with the blessing of the government \u2013 maintain oversight and control over them. In such a closed-source arrangement, customers would have no control over the weights of the models \u2013 essentially the tweaks that determine the choices the models make.<\/p>\n<p>On the other side of the argument, open-source advocates maintain that the only way to defend against cyberattacks by advanced AI is to equip defenders with the same tools. In the case of OpenAI and Hugging Face, the latter company was only able to detect an attack because it used GLM 5.2, a Chinese open-source model, to perform its security analysis.<\/p>\n<p>In a letter posted on social media on July 24, Nvidia CEO Jensen Huang \u2013 a longtime open-source advocate \u2013 declared that <em>\u201cdefenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats.\u201d<\/em><\/p>\n<p><em>\u201cRelying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect,\u201d<\/em> he continued. <em>\u201cAnd concentrating advanced AI capabilities behind a small number of closed models compounds that risk. Open weight models, on the other hand, allow a broad community of researchers and developers to examine their behavior, identify vulnerabilities, develop safeguards, and improve them over time.\u201d<\/em><\/p>\n<blockquote><p>\n        <span><strong>Read more<\/strong><\/span><\/p>\n<figure>\n            <img decoding=\"async\" src=\"https:\/\/mf.b37mrtl.ru\/files\/2026.06\/thumbnail\/6a39622d85f54035f916456d.jpg\" alt=\"RT\"><figcaption><a href=\"https:\/\/www.rt.com\/news\/641979-ai-attack-governments-warning\/\">AI \u2018months away\u2019 from taking down governments \u2013 intelligence group<\/a><\/figcaption><\/figure>\n<\/blockquote>\n<p>The letter was signed by more than two dozen companies working in the AI field. Two notable exceptions were OpenAI and Anthropic, although OpenAI added its signature later.<\/p>\n<p>However, it appears in the US that the closed-source argument will win out. On August 1, an executive order issued by US President Donald Trump in June comes into effect, requiring AI firms to submit advanced models to the government for approval 30 days before release. The Trump administration has also considered banning open-source Chinese AI models \u2013 a move <a href=\"https:\/\/swentr.site\/news\/642432-ai-digital-nuclear-weapons\/\" target=\"_blank\" rel=\"noopener noreferrer\">supported by the CIA<\/a> that would ensure OpenAI and Anthropic\u2019s dominance in the field. Shortly after the executive order was issued, former Trump AI adviser David Sacks noted that <em>\u201cthe leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open source competition.\u201d<\/em><\/p>\n<p>Every new incident of an AI <em>\u201cescape\u201d<\/em> only reinforces their bid for total control.<\/p>\n<p><strong><\/p>\n<p><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sam Altman\u2019s company claims that its most powerful model can execute complex hacking operations on&#8230;<\/p>\n","protected":false},"author":0,"featured_media":3047,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-3046","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-world-news"],"_links":{"self":[{"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=\/wp\/v2\/posts\/3046","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3046"}],"version-history":[{"count":0,"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=\/wp\/v2\/posts\/3046\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=\/wp\/v2\/media\/3047"}],"wp:attachment":[{"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3046"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3046"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.arabnewsmonitor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3046"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}