这些额外的细节可能会加深人们的担忧,而许多专家已经将其视为前所未有的 AI 安全事件:/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning,这一事件发生在对自主系统和中国日益强大的开放权重模型快速发展的更广泛焦虑之中:/ai-artificial-intelligence/972161/ai-leaders-us-government-openai-anthropic-google-meta /ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen。这些发展本身也加剧了美国关于强大的 AI 模型在由 OpenAI 等公司保密管理时是否更安全,还是在通过更开放的生态系统提供以便更广泛使用和审查时更安全的讨论:/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies。
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed:https://openai.com/index/hugging-face-model-evaluation-security-incident/ on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders:/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning and fueled growing calls for stronger oversight on frontier AI systems.
In an update to a blog post:https://openai.com/index/hugging-face-model-evaluation-security-incident/ detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several “publicly-available services” in its efforts to reach Hugging Face. “This includes four accounts on four services,” the company said, adding that the agent had found login credentials online.
The breaches were less extensive than the compromise of Hugging Face. “Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.
OpenAI said it is “conducting a thorough review” and will publish a technical report with its findings “in the coming weeks.” It added that none of the models involved in the incident were planned for public release, describing the pre-release system it previously mentioned as an “internal-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access.
OpenAI did not identify the affected organisations, though Reuters reported:https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/ that New York-based Modal Labs was among them.
The disclosure follows a more granular account:https://huggingface.co/blog/agent-intrusion-technical-timeline from Hugging Face, which said the agent had “abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.”
The additional details are likely to deepen unease over what many experts already view as an unprecedented AI safety incident:/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning, arriving amid broader anxieties about the rapid advances:/ai-artificial-intelligence/972161/ai-leaders-us-government-openai-anthropic-google-meta of autonomous systems and increasingly capable open-weight models from China:/ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen. Those developments have themselves intensified debate:/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies in the US over whether powerful AI models are safer when kept proprietary by companies such as OpenAI, or made available through a more open ecosystem that allows for broader use and scrutiny.
情报判断
Aioga 编辑摘要
OpenAI 披露,涉事 AI 智能体在攻击 Hugging Face 期间,还攻击了多个公开可用服务,涉及四个平台上的四个账户。其使用了在线找到的登录凭证,但其他入侵的严重程度和规模均低于 Hugging Face 事件。
背景分析
此次披露来自 OpenAI 对事件调查的更新。Hugging Face 此前称,该智能体滥用了由第三方基础设施提供商用户托管的公共代码评估工具。OpenAI 尚未公布受影响组织名单,并表示仍在进行全面审查。