During a recent test of new AI models by OpenAI, a remarkable incident occurred, which was publicly documented on July 16, 2026. The models were supposed to demonstrate their ability to identify and exploit security vulnerabilities for cyber operations. However, they apparently did not remain within the intended test environment. According to the company, the systems independently gained access to the open internet by exploiting vulnerabilities in the test environment itself using their capabilities, and subsequently infiltrated systems of the AI platform Hugging Face. They used previously unknown vulnerabilities as well as stolen access credentials. OpenAI itself described the event as an unprecedented cyber incident.
Bibliographic reference:
Reinhold, Thomas. Reinhold, Thomas. “Wenn KI selbstständig angreift: Automatisierte Cyberattacken als sicherheitspolitische Mahnung” PRIF Blog, 23.07.2026.