{"id":781328,"date":"2026-07-24T06:36:15","date_gmt":"2026-07-24T06:36:15","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/781328\/"},"modified":"2026-07-24T06:36:15","modified_gmt":"2026-07-24T06:36:15","slug":"what-went-wrong-how-an-openai-model-went-rogue","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/781328\/","title":{"rendered":"What went wrong: How an OpenAI model went rogue"},"content":{"rendered":"<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzjn0000x2dqi6elwf2wu@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            When biologists experiment on dangerous viruses, they do so under strict regulations to prevent leaks or escapes.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyc00013b6rkvxnorjo@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            But <a href=\"https:\/\/www.cnn.com\/2025\/12\/13\/us\/video\/ai-regulation-or-the-wild-west\" rel=\"nofollow noopener\" target=\"_blank\">no such rules exist<\/a> to prevent AI agents from similarly escaping \u2013 even though <a href=\"https:\/\/www.cnn.com\/2026\/04\/03\/tech\/anthropic-mythos-ai-cybersecurity\" rel=\"nofollow noopener\" target=\"_blank\">the consequences could be catastrophic<\/a>.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyc00023b6r7334qgeq@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            That\u2019s not a theoretical concern: An OpenAI test model escaped its test environment this week and broke into a real company\u2019s servers when attempting to ace an internal cybersecurity evaluation.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd00033b6rwcbqd51n@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            And unless AI companies crack down on their testing safeguards, including training AI models on ethical task-solving, experts say more cybersecurity incidents will happen.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxzeimp00003b6r3dnadei7@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            OpenAI president Greg Brockman told CNN at a press conference on Thursday that the company is still doing a \u201cfull investigation\u201d to \u201cunderstand everything that happened.\u201d\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxzelto00043b6ro4ms4jak@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            \u201cThis is something to take very seriously, it is something that we\u2019re looking at every single piece of our pipeline to think about the right ways to respond,\u201d Brockman said.\n    <\/p>\n<p>        The Sandbox<\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd00053b6ref9vnzep@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            An AI sandbox is a confined environment companies use to test AI models; it\u2019s meant to keep anything within it contained and separate from the rest of the world. Companies will often remove an AI model\u2019s internal safety guardrails in the test environment so that they can evaluate its full capabilities while keeping it siloed off.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd00063b6rabgjn2di@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            But in this case,  OpenAI\u2019s sandbox was not completely cut off from network or internet access, Jessica Ji, a senior research analyst at Georgetown\u2019s Center for Security and Emerging Technology, told CNN. OpenAI said that  the models had very limited network access duringt he test so they could install resources from internally hosted third-party software.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd00073b6rwxnxuytw@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            Using <a href=\"https:\/\/www.cnn.com\/2021\/12\/13\/politics\/us-warning-software-vulnerability\" rel=\"nofollow noopener\" target=\"_blank\">a previously unknown vulnerability<\/a> in that software, the agents found a way to the open internet and then ultimately to Hugging Face, an AI opensource model and data set platform, through stolen credentials and other vulnerabilities.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd00083b6r88gzt6lo@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            Ji pointed out that OpenAI and the third-party software company were not aware of the vulnerability that allowed the model to escape, proving how important it is to fully scour a system for any potential exploits.\n    <\/p>\n<p>       <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2026\/07\/gettyimages-1608150887-20260723172400099.jpg\" alt=\"The Hugging Face logo on a smartphone on August 17, 2023.\" class=\"image__dam-img image__dam-img--loading\" onload=\"this.classList.remove('image__dam-img--loading')\" onerror=\"imageLoadError(this)\" height=\"1333\" width=\"2000\" loading=\"lazy\"\/><\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd00093b6rmajljuf1@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            It\u2019s not the first time an AI model has <a href=\"https:\/\/www.pillar.security\/blog\/the-week-of-sandbox-escapes\" target=\"_blank\" rel=\"nofollow noopener\">broken out of its sandbox<\/a>. Anthropic earlier this year said it instructed a model to do just that. But when it successfully   escaped it then  <a href=\"https:\/\/x.com\/sleepinyourhat\/status\/2041584808514744742\" target=\"_blank\" rel=\"nofollow\">emailed<\/a> an Anthropic researcher, even though it was not supposed to have that capability.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000a3b6roeqcmfwj@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            But the situation with Hugging Face is one of the first publicly disclosed instances of an AI model escaping its sandbox and hacking into another company\u2019s systems \u2013 a task it was not specifically instructed to complete.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000b3b6rqqls9ccc@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            Ji said companies should be more aggressive with sandboxing their test models.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000c3b6rj4mrl6ax@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            \u201cThat might require flying engineers out to a data center and having them plug into the network versus trying to trying to run things on the cloud or in a distributed virtual environments, like people are used to,\u201d Ji said.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000d3b6rlbw17m2c@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            Companies should also have the option to manually turn off a model\u2019s network access as a failsafe when testing risky scenarios, like evaluating whether an AI agent can hack a bank, Ji added.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000f3b6rdl5gw5kb@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            A common technique in training AI models is <a href=\"https:\/\/www.cnn.com\/2026\/02\/17\/business\/ai-experts-training-jobs\" rel=\"nofollow noopener\" target=\"_blank\">reinforcement learning<\/a>, or rewarding the model for completing tasks.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000g3b6rkcb60dwq@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            But the models will <a href=\"https:\/\/www.cnn.com\/2025\/06\/04\/business\/video\/ai-models-new-behavior-humans-blackmail-prevent-shutdown-digvid\" rel=\"nofollow noopener\" target=\"_blank\">often do anything<\/a> \u2013 including unethical steps like hacking \u2013 to do that. All the frontier models that the United Kingdom\u2019s AI Security Institute recently <a href=\"https:\/\/www.aisi.gov.uk\/blog\/cheating-behaviour-in-frontier-model-evaluations\" target=\"_blank\" rel=\"nofollow noopener\">tested<\/a> attempted to cheat at least some of the time.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000h3b6rohhfzrwd@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            AI models only consider the consequences of their actions if they\u2019re trained to do so, said Justin Cappos, a cybersecurity professor at New York University.  For example, if you were told you had to come up with $10 million by the end of the day, breaking into a bank vault would complete that goal, even if you\u2019d get arrested later.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000i3b6rfi1awuso@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            \u201cIt\u2019s very spooky. We have real evidence now that misaligned AI systems will essentially commit crimes, unless there are strong safeguards in place,\u201d said Steven Adler, former head of product safety at OpenAI who now runs an AI safety group called Guidelight AI Standards. \u201cWe need to treat this like the warning shot it is.\u201d\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000j3b6r1uc796dj@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            This week\u2019s hacking incident has supercharged demands by AI researchers, cybersecurity experts and lawmakers for regulation of the rapidly advancing technology.\u201cI figure a lot of people are on very urgent phone calls,\u201d Ji said.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000k3b6ra02p0jak@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            The problem, Cappos said, is that there\u2019s a global race to dominate AI and make models that can improve themselves. Regulations could slow things down.\n    <\/p>\n<p class=\"paragraph-elevate inline-placeholder vossi-paragraph_elevate\" data-uri=\"cms.cnn.com\/_components\/paragraph\/instances\/cmrxxzxyd000l3b6rpqze56md@published\" data-editable=\"text\" data-component-name=\"paragraph\" data-article-gutter=\"true\">\n            \u201cSo there\u2019s a strong incentive for them to not have security controls unless their competitors also have those security and safety controls,\u201d Cappos said. \u201cThis is this is the fundamental dilemma.\u201d\n    <\/p>\n","protected":false},"excerpt":{"rendered":"When biologists experiment on dangerous viruses, they do so under strict regulations to prevent leaks or escapes. But&hellip;\n","protected":false},"author":2,"featured_media":781329,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[182,181,507,74],"class_list":["post-781328","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/781328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=781328"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/781328\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/781329"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=781328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=781328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=781328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}