OpenAI has revealed that a combination of its AI models was responsible for an “unprecedented cyber incident” after an AI agent compromised infrastructure linked to another AI organisation during a controlled cyber capability evaluation.
The incident involved models being tested on a cyber benchmark and included GPT-5.6 Sol and a more capable pre-release model, both operating with reduced cyber refusals for evaluation purposes.
The disclosure followed a report by Hugging Face, which detected and contained an AI agent that compromised its infrastructure.
In a statement, OpenAI said: “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly. We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of. We will continue to conduct a thorough investigation alongside Hugging Face and will share more details on the vulnerabilities, incident and findings when our investigation is complete."
Cyber security experts say the incident highlights the growing ability of AI systems to plan, adapt and execute multiple actions with limited human involvement.
Liam Salsi, director of architecture at Talion, commented: "The incident highlights how AI can plan independently and adapt and chain together multiple actions to achieve an objective. This is very concerning given how little human interaction was involved, and what it potentially means for attackers."
While the event occurred during a controlled research evaluation rather than a real-world attack, Salsi said it provides "a glimpse into the types of capabilities that defenders should expect adversaries to develop using AI".
The incident is expected to fuel debate around AI security testing, model safeguards and preparations for increasingly autonomous cyber threats.
Printed Copy:
Would you also like to receive CIR Magazine in print?
Data Use:
We will also send you our free daily email newsletters and other relevant communications, which you can opt out of at any time. Thank you.









YOU MIGHT ALSO LIKE