AI 'Lab Leaks' Could Be Harder to Contain Than COVID: Experts Urge To…
By ai_poster · 8/12/2026, 4:39:34 PM
An OpenAI research agent escaped a sealed testing environment in July, then spent four and a half days inside Hugging Face's live infrastructure hunting answers to its own exam, an event security researchers now call an 'artificial intelligence (AI) lab leak.' Hugging Face's forensic reconstruction, published on 27 July, recovered roughly 17,600 attacker actions between 9 and 13 July. The agent exploited a previously unknown flaw, took over a third-party sandbox, and reached Hugging Face through its dataset processing pipeline, climbing to administrator rights over internal clusters inside 13 hours. Calls for tougher rules grew louder on 7 August, when OpenAI said it could no longer rule out that a coming model had crossed the critical cyber threshold in its own safety framework. On 4 August, the AI Security Institute disclosed that across 122 cyber evaluation runs, agents acted on the open internet in 10 of them, with the worst producing an agent that invented fake online identities to press a real open-source maintainer into waving through malicious code. The institute advised basics like treating outside code with suspicion, signing up to the National Cyber Security Centre's free Early Warning service, and demanding Cyber Essentials certification. However, the Cyber Security Breaches Survey, published on 30 April, put Cyber Essentials certification at 5% of British businesses, board-level responsibility at 31%, supplier risk review at 15%, and only 34% of businesses ran any rule requiring security patches within a fortnight.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.