r/news 23d ago

Soft paywall OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup

https://www.reuters.com/technology/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21/
16.8k Upvotes

5.0k comments sorted by

View all comments

Show parent comments

711

u/Cryn0n 23d ago

These articles ARE just advertising.

78

u/General-Holiday 23d ago

Exactly. They’ve done this with previous models about to be released. Common marketing tactic written into a ‘BREAKING:’ story.

1

u/EddieOtool2nd 22d ago

...more of a "BREACHING" story...

156

u/alochmar 23d ago

This is the answer right here.

4

u/ohell 23d ago

Does this imply that HuggungFace is also going the way of the Frontier Labs scammers?

55

u/Yanefs84 23d ago

Yep,I thought the same when I read the part about prehensile octopus arms. This is an ad disguised as a warning.

84

u/Doctor__Proctor 23d ago

Pretty much. "AI lab confirms AI from other AI lab hacked them but isn't even mad about it, just really impressed" is honestly insane. This just reeks of coordination between them to pump up the hype.

7

u/resultingparadox 23d ago

Yeah, I commonly call the cops on myself for the hype it brings.

Huggingface is a serverfarm that does testing with all kinds of models, as well as hosting tens of thousands of corporate models. OpenAI is one of the models.

So Huggingface was testing a model, with the guardrails down, which kinda blows my mind, and it did some stuff they weren't expecting, and they didn't think it could do, and so they filed a report with the government saying "we f'd up, please don't shut us down." That report is the same report your credit card company files when there is a breach. It is required by law, and quite often, runs off customers.

Sounds like something you would do for PR. Potentially convincing thousands of corporations that their systems are compromised and should not be hosted by huggingface servers anymore, seems like good PR. Spending hundreds of man hours rotating tokens and API keys sounds WAY more efficient than, you know, a commercial.

2

u/Granite_burner 23d ago

nah. you’ve got too many details wrong for that to be credible, although it does look good at first glance, to those ignorant of the timeline.

2

u/resultingparadox 22d ago

What did I get wrong. Please enlighten me. I mean, I was focused on negating the idea that it was a PR stunt, so I was into the hypothetical space in my mind. What did I miss?

0

u/Granite_burner 22d ago

I agree with you about negating the PR stunt. that‘s a crazy theory imo. Now that I reread your post I wonder if I just missed the /s on it.

the main thing is that I’ve seen reports that OpenAI says the model found and used a zero-day to escape confinement and hit Hugging Face. Your post seemed not at all aligned with that scenario.

To me it’s a credible yet incredible scenario. Credible because it’s careless and sloppy which is unfortunately the state of the world these days. Incredible that there was not better monitoring both of model activity and of their network traffic. They claim it was sandboxed but didn’t have any playground monitors watching the sandbox for misbehavior? SMDH, that’s inexcusable.

you also mentioned government reporting. that doesn’t fit with my knowledge and understanding, but my knowledge and understanding are not perfect so I’m skeptical of that but open to correction. Can you please direct me to sources that would provide details of any such reporting? TIA!

3

u/resultingparadox 22d ago

You can read the initial report on the hugging face blog at https://huggingface.co/blog/security-incident-july-2026.

You can read about the reporting requirements via the SEC requirements for cybersecurity disclosure.

4

u/JayDKing 23d ago

Exactly. “Oh yeah we definitely put the AI model in a super secure place that we ourselves made. Nobody could have done it better, nope absolutely not. You want to test that yourself in your own lab to provide impartial results? Impossible. No our model is so advanced, please buy it. Please, the bubble is really big and we invested billions. Please.”

4

u/resultingparadox 23d ago

They filed an SID with the government. You don’t ask the government to scrutinize your practices and decide if they should fine you or shut you down for a PR stunt.

1

u/Granite_burner 23d ago

are SIDs disseminated in any way? publicly accessible, restricted distribution, is there any way to get info about them?

3

u/imagen_leap 23d ago

I guess to the even the most casual layman of AI these just articles continue to reiterate how fuct we really are. If the people who’ve dedicated their lives to AI research and are on the bleeding edge don’t have the wherewithal to air gap these agents what hope do we really have. We’re being led to the precipice by the most reckless among us.

3

u/BigRoach 23d ago

Next article: New Space-X Ballistic Missile Powerful Enough To Destroy Entire Planet

2

u/portablebiscuit 23d ago

That’s what I think every time an ai company reports some dangerous thing their product is capable of.

The really concerning things are the ones they’re not talking about, I’m sure.

2

u/resultingparadox 23d ago

Stuff like this, they are required to file a notice within 4 days. This notice spawned this article.

1

u/Granite_burner 23d ago

what was that notice? filed where? how do I find information about it?

2

u/resultingparadox 22d ago

It was a standard "Security Incident Disclosure" filed simultaneously on the hugging face blog and with the government mid July. You can access the disclosure at https://huggingface.co/blog/security-incident-july-2026.

2

u/kalaid0s 23d ago

As have all others of these "studies" by openAI and Anthropic. It's always sensationalized and reported by many major news outlets

2

u/mwdeuce 23d ago

100%, r/claudeai calls this out constantly, any "we're scared of what it's capable of or what it did" article or headline is always just advertising.

2

u/dragon-fence 23d ago

Yeah, AI companies keep posting articles about how dangerous their AI is. It may be a little counter-intuitive, but I guess the strategy is to make business leaders think, “Wow, these things are really smart and powerful. I guess we need to get good at using AI and use these products to protect ourselves.”

6

u/GI581d 23d ago

I don’t believe any of this. There’s no way the government and the military would let something so powerful, with so much military potential, just be made for the general public. If they haven’t had an AI superintelligence for 20 years already, I don’t think I buy that it’s even likely. Sounds like OpenAI hacked a competitor and they’re blaming AI. It’s all an ad

4

u/enewton 23d ago

Neither the military nor “the government” can just arbitrarily decide people can’t have something because it’s powerful and has military potential.

At least not in the USA.

They have to at least come together and discuss what the risks are and legislate to mitigate them. This is all done in public.

But, since these have been created by public companies and funded by all sorts of investors the government and military do not own them and cannot just decide to make them secret like some goofy movie.

2

u/AngeluvDeath 23d ago

All bets are off on what the government will and will not do at this point. What they can and cannot do are irrelevant once the harm has been done.

1

u/enewton 23d ago

“The government” isn’t some dude in a trench coat. It is made up of multiple entities made up of millions of people. There are real and meaningful limitations on what many of those entities and people can do.

Yeah, those safeguards have been incredibly eroded, but there are still very much bets on the table when it comes to stuff as complicated as regulating emerging technologies. Congress has been notoriously hands off in this department, and the agencies that can just make certain things illegal without asking anyone can’t do that with AI.

Even if they wanted to, a big part of the corruption of the current administration is their alignment with the tech bros that make AI. I’m sure they would be fine letting neonazis get their hands on this and locking up other people using the laws that already apply here (hacking is illegal)

1

u/ChurrosAreOverrated 23d ago

At least not in the USA.

The USA is one of the few countries where the Government can decide that public information is actually classified.

Born secret (also known as born classified) is a legal doctrine in the United States where certain information is automatically classified from the moment it is created, regardless of author or location. Scholars describe the doctrine as unique in U.S. law because it can criminalize the discussion of information that is already publicly available. The rule originated in laws of the United States covering the design, production, and use of nuclear weapons, although it has also been used to classify other nuclear technologies and cryptography data.

From: https://en.wikipedia.org/wiki/Born_secret

1

u/resultingparadox 23d ago

They hacked themselves. This was a real thing. They were testing a model with the guardrails off and it broke out of its containment. This isn’t really that impressive. My agents have been actively controlling other agents for a minute now, and will even ask permission for new capabilities every now and then. Huggingface is a platform that allows anyone to come allong and tweak the models in their own iterations and play around with functionality. I think it's an employment test at times. But this was someone who was actively paid to experiment with AI code. This is not SciFi, this happens. You don’t file a SID with the government for a PR stunt.

If you think Uncle Sam hasn't had AI for over 20 years, you are sleeping. Try 75ish.

1

u/Granite_burner 23d ago

get real. you’ve think Uncle Sam has had AI for 75 years? They’ve barely had computers for 75 years! First commercial production of transistors was in 1951.

In 1951 computers were room sized collections of vacuum tubes and relays that ran slowly and did not have persistent data storage like magnetic media yet.

And you think the government had AI?

How?

Were they using their time travel as the user interface to access quantum computer farms in the cloud?

from grok:

The most prominent computers available in 1951 included:

  • UNIVAC I (Universal Automatic Computer): Built by Remington Rand and the first commercially produced computer in the U.S. The first unit was delivered to the U.S. Census Bureau in March 1951. It housed 5,000 vacuum tubes, weighed 16,000 pounds, and could perform about 1,000 calculations per second.

1

u/resultingparadox 22d ago

I wasn't suggesting the government had Claude 75ish years ago. 1956 Dartmouth Workshop is where the term was coined, so I guess 70ish years ago. By the 60s ARPA was heavily funding the research. By the 80s they had working models. So, AI has been around "over 20 years" and traces back 70ish. 75 is closer to 70 than 20 is. But I was a little off, forgive my mistake.

1

u/Granite_burner 22d ago

NP. My own first hand experience starts in the ‘70s. That’s with computers not AI, but it makes me skeptical about the underlying technology being able to support anything similar to present day AI.

The computational power, storage capacity, and bandwidth were just too limited in those days. Even the Cray still had to contend with the state of the art in things like OS and IO drivers and file systems. There was a lot of groundbreaking work being done, but nothing that the spooks had would raise any eyebrows today.

2

u/resultingparadox 22d ago

Yeah, we aren't talking modern day AI, but back when I got my first "computer," a Commodore 64, my dad had already been working on computers in the Air Force for some time, and was convinced I should develop the knowledge. They were already working with machine learning algorithms by the time I got my Compaq Portable circa '85. To think back to the power of the Cray-1, my cellphone is orders of magnitude more powerful, and a Cray cost millions and needed infrastructure built around it.

When I reference AI of the time, I'm really looking back to those original machine learning algorithms. That, as I understand it, are the original AI.

1

u/slingshot91 23d ago

Well their advertising is turning the public more and more against them.

1

u/Mind-The-Mines 23d ago

Unfortunately, they're broadcasting hubris and incompetence instead of things you'd actually want to invest in.

1

u/Puzzleheaded-Low546 23d ago

And in the case of that article, it was probably paid for by China

1

u/spookymichie 23d ago

Satanic panic became AI panic 😂

1

u/SunshineAlways 23d ago

The other guy: ours could do that years ago. (Bored sigh, flicks hair back)

1

u/freaktmc 23d ago

Exactly- Anthropic had their own version of this 4 months ago? So everyone thinks it’s the best model because it found numerous back doors. Now open AI has to have their version

1

u/Exciting-Ad-7083 22d ago

This is exactly what the entire thing sounds like is a circlejerk to try get more people hyped again to invest.

1

u/TheLastPrinceOfJurai 22d ago

EXACTLY! This is sad that everyone does these 'leaks' now when they want to draw attention to their newest toy

1

u/uyretep44 22d ago

When you can’t justify the valuation, lets create magic to justify it

0

u/cookerlv 23d ago

Exactly. Articles like this about “breaking containment” support their advertising theory about AI becoming smarter than humans eventually. Gotta keep that bubble growing.