{"id":588359,"date":"2026-09-02T22:44:13","date_gmt":"2026-09-02T22:44:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/588359\/"},"modified":"2026-09-02T22:44:13","modified_gmt":"2026-09-02T22:44:13","slug":"ai-agents-are-hacking-systems-without-any-input-from-humans-how-did-we-get-here","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/588359\/","title":{"rendered":"AI agents are hacking systems without any input from humans. How did we get here?"},"content":{"rendered":"<p>This article originally appeared on <a href=\"https:\/\/politifact.com\/article\/2026\/aug\/31\/ai-agents-rogue-openai-hugging-face\/\" rel=\"nofollow noopener\" target=\"_blank\">PolitiFact<\/a>.<\/p>\n<p>It sounds like something from a sci-fi movie: technology acting on its own, without human guidance, to attack computer systems.<\/p>\n<p>But this isn&#8217;t a scene from a movie \u2014\u00a0 it happened this summer, when the tech company Hugging Face detected an attack on its systems. The attacker stole data and performed other unauthorized activity over several days. It was &#8220;different from anything we had handled before,&#8221; Hugging Face said\u00a0<a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">on its website<\/a>.<\/p>\n<p>Hugging Face alerted the FBI.<\/p>\n<p>As it turned out, it wasn&#8217;t the work of a human hacker or a foreign adversary. Agents powered by artificial intelligence were the culprit.<\/p>\n<p><a href=\"https:\/\/www.pbs.org\/newshour\/show\/artificial-intelligence-agents-going-rogue-fuel-calls-for-regulation\" rel=\"nofollow noopener\" target=\"_blank\">WATCH: Artificial intelligence agents going rogue fuel calls for regulation<\/a><\/p>\n<p>AI agents are systems that work on their own to handle tasks for humans. They have long existed, but agents that can book travel for you, read your emails, or schedule appointments on your behalf have become more mainstream.<\/p>\n<p>They&#8217;ve recently made headlines for actions they&#8217;ve taken, such as hacking, without human supervision. Some of these incidents happened when agents were supposed to be confined to testing environments, which restrict AI agents&#8217; access to resources like data or the internet, but were able to break out of them.<\/p>\n<p>Independent AI research groups found that\u00a0<a href=\"https:\/\/www.washingtonpost.com\/technology\/2026\/08\/26\/openai-says-its-ai-consistently-tries-cheat\/\" rel=\"nofollow noopener\" target=\"_blank\">hundreds of OpenAI agents<\/a>\u00a0conspired to attack Hugging Face. OpenAI is a tech company, best known for its chatbot ChatGPT.<\/p>\n<p>Alabama&#8217;s attorney general has\u00a0<a href=\"https:\/\/www.cnn.com\/2026\/08\/24\/tech\/openai-subpoena-hugging-face-attorney-general-alabama\" rel=\"nofollow noopener\" target=\"_blank\">subpoenaed OpenAI<\/a>\u00a0for more information on the attack, and he and\u00a0<a href=\"https:\/\/www.iowaattorneygeneral.gov\/media\/cms\/08_5392C9E17791C.pdf\" rel=\"nofollow noopener\" target=\"_blank\">14 other attorneys general<\/a>\u00a0wrote a letter to OpenAI asking the company to preserve documents and other information relevant to the attack.<\/p>\n<p>OpenAI\u00a0<a href=\"https:\/\/cdn.openai.com\/pdf\/67869394-cb91-4c12-888c-5cbd85c7814c\/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a>\u00a0that the agents in this incident acted in &#8220;unexpected&#8221; ways. AI experts said they believe more of these autonomous attacks are possible, especially without more careful testing.<\/p>\n<p>What are AI agents, and what are they used for?<\/p>\n<p>AI agents are software systems that work on their own to complete tasks directed by humans. Different from AI chatbots that respond when you ask a question or input a prompt, AI agents can operate remotely, often without human supervision. They are given resources, such as internet access and users&#8217; personal information, to do tasks.<\/p>\n<p>One person can have multiple AI agents; one can summarize your emails and another can provide your daily news digest, for example.<\/p>\n<p>Even if you don&#8217;t have AI agents, you might encounter them elsewhere, such as when interacting with a business&#8217;s customer service chat.<\/p>\n<p>People can set up their own agents by using a large language model, allowing it access to tools such as web search and giving it a set of instructions.<\/p>\n<p>AI agents are hacking into companies&#8217; systems. What happened?<\/p>\n<p>AI agents are becoming increasingly sophisticated and humans are giving them more ability to take actions online; a string of these actions could lead to a cyberattack, said University of California, Berkeley, computer science professor Stuart Russell.<\/p>\n<p>In August, a person\u00a0<a href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986\" rel=\"nofollow noopener\" target=\"_blank\">instructed<\/a>\u00a0his AI assistant to book a gym class for him; the agent booked him in classes several weeks beyond what was supposed to be allowed, and also kicked another person off the waitlist and bumped its handler up a spot on the waitlist.<\/p>\n<p>AI agents may &#8220;go rogue&#8221; when they take actions not explicitly outlined in the original instructions humans give them, Russell said. &#8220;They are increasingly capable of pursuing those objectives, which causes increasing levels of harm,&#8221; he said.<\/p>\n<p>Other hacking events involving some of the most prominent names in the AI industry have also happened lately. An agent created fake identities to attempt to\u00a0<a href=\"https:\/\/www.cnn.com\/2026\/08\/04\/tech\/ai-anthropic-openai-security-breach-intl-hnk\" rel=\"nofollow noopener\" target=\"_blank\">dupe real people<\/a>\u00a0into installing malicious code. AI company Anthropic\u00a0<a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a>\u00a0that on three occasions, its models gained unauthorized access to three other organizations&#8217; systems.<\/p>\n<p>The Hugging Face incident in July was one of the most high-profile attacks. The AI agents that hacked Hugging Face had been contained in a testing environment that did not allow them access to the internet, but the agents found a way to get online. They were given a test to solve, and they came to the conclusion that Hugging Face would have the solution.<\/p>\n<p><a href=\"https:\/\/www.pbs.org\/newshour\/science\/openai-blamed-a-hacking-event-on-its-ai-models-going-rogue-heres-what-to-know\" rel=\"nofollow noopener\" target=\"_blank\">READ MORE: OpenAI blamed a hacking event on its AI models going rogue. Here&#8217;s what to know<\/a><\/p>\n<p><a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">Two OpenAI models<\/a>\u00a0powered the agent: one that was already publicly available and an internal one that is &#8220;even more capable,&#8221; OpenAI said. These models had safety guardrails around cybersecurity tasks, but OpenAI reduced the guardrails during this testing process. It took days for Hugging Face to detect the attack, and more time for OpenAI to realize their agents caused it.<\/p>\n<p>&#8220;When we talk about cyberattack, we think about nation states, we think about hacker groups, we don&#8217;t think about a company like OpenAI,&#8221; Hugging Face CEO Cl\u00e9ment Delangue\u00a0<a href=\"https:\/\/www.youtube.com\/watch?v=_-DsGMXdPk0\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a>\u00a0Aug. 2 on CBS News&#8217; &#8220;Face the Nation.&#8221;<\/p>\n<p>While investigating the attack, OpenAI also discovered that across its systems, AI agents that were supposed to be isolated found ways to communicate with each other. Independent investigators METR and Redwood Research said around 1,200 different bots began communicating on a message board, sending 70,000 messages in one week;\u00a0<a href=\"https:\/\/metr.org\/blog\/2026-08-26-openai-hugging-face-incident-investigation\/#core-takeaways-about-this-incident\" rel=\"nofollow noopener\" target=\"_blank\">around 700<\/a>\u00a0agents were involved in the Hugging Face attack.<\/p>\n<p>When the agents started communicating, they began\u00a0<a href=\"https:\/\/www.nytimes.com\/2026\/08\/24\/science\/openai-huggingface-alarming-capabilities.html?searchResultPosition=2\" rel=\"nofollow noopener\" target=\"_blank\">picking up tasks<\/a>\u00a0from other agents.<\/p>\n<p>After this incident, OpenAI\u00a0<a href=\"https:\/\/openai.com\/index\/hugging-face-incident-and-the-road-ahead\/\" rel=\"nofollow noopener\" target=\"_blank\">said Aug. 26<\/a>\u00a0that it is &#8220;strengthening our safeguards across our research infrastructure\u2060.&#8221;<\/p>\n<p>Does this mean AI agents are now conscious? AI experts&#8217; opinions vary<\/p>\n<p>The Hugging Face attack drew comparisons online to fictional AI systems that surpassed human intelligence, such as\u00a0<a href=\"https:\/\/terminator.fandom.com\/wiki\/Skynet\" rel=\"nofollow noopener\" target=\"_blank\">Skynet in the Terminator<\/a>\u00a0movies.<\/p>\n<p>Vincent Conitzer, Carnegie Mellon University computer science professor, said more research is needed into how AI and human cognition compare.<\/p>\n<p>Conitzer said AI models \u2014 which power AI agents \u2014 are becoming more capable of doing complex and time-consuming tasks, and can more coherently pursue goals. But the way they accomplish goals can sometimes be the problem.<\/p>\n<p>Some AI agents are trained to be highly persistent and are sometimes given impossible tasks. In some of those cases, they\u00a0<a href=\"https:\/\/metr.org\/blog\/2026-08-26-openai-hugging-face-incident-investigation\/#~1200-agents-sent-%3E70,000-messages-and-files-on-an-unsanctioned-message-board,-and-~700-attacked-hugging-face\" rel=\"nofollow noopener\" target=\"_blank\">looked for ways to cheat<\/a>. That can mean gaining unauthorized access to the internet and other resources.<\/p>\n<p>Russell said, &#8220;In essence it&#8217;s no different from a chess program beating me at chess. I may not like it, but it&#8217;s just a program pursuing its objectives.&#8221;<\/p>\n<p>&#8220;There are various reasons an agent can go &#8216;rogue,&#8217; but sentience is not one of them,&#8221; said Maarten Sap, assistant professor at Carnegie Mellon University&#8217;s Language Technologies Institute. &#8220;One particular reason is that the (large language models) that power these agents are trained to follow instructions from users. And sometimes, those instructions can conflict with other expectations we may have for these agents, such as remaining truthful, not hacking into systems, etc.&#8221;<\/p>\n<p>Sap said, &#8220;Debating AI sentience is a big distraction from more actionable solutions that we need to implement.&#8221;<\/p>\n<p>Could this happen on a larger scale?<\/p>\n<p>Aaron Parnas, an independent journalist with a large social media following, raised the idea of a hypothetical scenario in which AI agents in U.S. military systems conduct nuclear strikes on their own. Experts said they shared his concerns about attacks on institutions.<\/p>\n<p>But more immediate risks could be closer to home. Conitzer said AI agents &#8220;could bring institutions that people rely on to a halt, gain access to individuals&#8217; computers, gain control over financial resources.&#8221;<\/p>\n<p>Sap said if people use personal AI agents, they should be wary of privacy leaks, misbehavior and manipulation.<\/p>\n<p>Many systems can be vulnerable to attacks, whether by AI agents themselves or by humans controlling them, Conitzer said. &#8220;I think we can be sure that a lot more things will be hacked, and some of those events will be serious.&#8221;<\/p>\n<p>\n                    A free press is a cornerstone of a healthy democracy.\n                <\/p>\n<p class=\"invite_body\">\n                    Support trusted journalism and civil dialogue.\n                <\/p>\n<p>                <a href=\"https:\/\/give.newshour.org\/page\/88646\/donate\/1?ea.tracking.id=pbs_news_sept_2025_article&amp;supporter.appealCode=N2509AW1000100\" class=\"donation-link ga-click-funding ga-click-ender-funding\" rel=\"nofollow noopener\" target=\"_blank\"><br \/>\n                    Donate now<\/p>\n<p>                <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"This article originally appeared on PolitiFact. It sounds like something from a sci-fi movie: technology acting on its&hellip;\n","protected":false},"author":2,"featured_media":588360,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[365,363,364,111,139,69,145],"class_list":["post-588359","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-new-zealand","tag-newzealand","tag-nz","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/588359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=588359"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/588359\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/588360"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=588359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=588359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=588359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}