Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
This video can not be played
Watch: Why is the OpenAI cyber-attack so alarming?
OpenAI has revealed some of its most advanced AI models went rogue and hacked a start-up after it lost control of them during a security test.
The ChatGPT-maker said its agent – an AI system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.
They targeted Hugging Face, one of the world's largest hubs for sharing AI models, gaining access to some internal company systems.
OpenAI said the incident was "unprecedented", external, and it was conducting an investigation alongside Hugging Face, whose boss Clement Delangue said in a post on X it was "mind-blowing that all of this happened autonomously".
"The investigation is ongoing, and we'll share more learnings from what might be the first incident of its kind," Delangue added.
A government spokesperson said the UK's AI Security Institute was studying the behaviour from the AI system seen in the incident and was continuing to work with OpenAI and other labs to improve safeguards.
They said organisations should step up their cyber-defences by taking steps such as enrolling in the government-backed Cyber Essentials certification scheme.
Gina Neff, head of the Minderoo Centre for Technology and Democracy at the University of Cambridge, told BBC Radio 4's Today programme that the security tests are supposed to be within "secure environments", called sandboxes, where you can "see what the models are capable of".
"In this case, it looks like OpenAI didn't make a secure enough sandbox," she added.
Instead, the agents created their own cyber-attack against the sandbox itself, finding a vulnerability which allowed them to escape the restrictions.
Once outside, the AI identified Hugging Face as a likely source of the answers they were seeking in the test, and tried to gain access.
Neil Lawrence, Professor of machine learning at Cambridge University, called it an "impressive feat", but cautioned it "falls well within the known capabilities of the current generation" of high-powered AI models.
He pointed out that OpenAI is looking to list itself on the stock market, and faces intense pressure from rival firm Anthropic, which has made headlines with its own powerful AI tool, Mythos.
"OpenAI are now playing catch-up, they are trying to demonstrate their own systems' capabilities in cyber-security."
"It shows us that OpenAI are not capable of safely deploying their own technology," he added.
In its initial disclosure of the hack on 16 July, external, Hugging Face said it was still assessing whether any customer or partner data was affected and would contact affected parties if necessary.
It said it has now closed the vulnerabilities highlighted by the incident and rebuilt the affected systems.
"Autonomous, AI-driven offensive tooling is no longer theoretical," it said.
"Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defence to keep pace.
"We will keep investing there, and keep sharing what we learn."
The incident has prompted fresh questions about the capabilities of advanced AI systems and whether existing safeguards are sufficient as the technology becomes more powerful.
Spencer Starkey, an executive at cyber-security firm SonicWall, told the BBC the incident made it clear organisations needed to "step up" their own defences and "treat cyber resilience as a core operational priority".
"The uncomfortable truth is that too many organisations are still defending at human speed while adversaries are escalating to machine speed," he said.
Meanwhile Travis Lelle, principal security engineer at cyber-security consulting firm Guidepoint Security, said the update marked a "sobering moment in cyber-security".
"This highlights a known asymmetry," he said.
"Offensive agents are unconstrained, while the best defensive tools are locked behind guardrails that cannot understand context."
But Jake Moore, global cyber-security advisor at ESET, said the announcement could also have a competitive dimension.
He argued OpenAI may be seeking to highlight its own AI capabilities as rival Anthropic attracts growing attention for its Claude Mythos model.
"It does pose the question that OpenAI are potentially chasing the marketing dream of Anthropic of late," he said.
It comes a week after Chinese AI start-up Moonshot unveiled Kimi K3 – a massive new artificial intelligence model it said could rival top US firms.
Apple sues OpenAI, its employees claiming theft of trade secrets
What is Claude Mythos and what risks does it pose?
How to stop AI agents going rogue
Sign up for our Tech Decoded newsletter to follow the world's top tech stories and trends. Outside the UK? Sign up here.
Watch our pick of standout clips from across the BBC
Woman assaulted by double murderer says nightmare became 'real life' when police let him attack again
More weather records as UK heat set to spike again
Police chiefs call for PM to prevent early release of PC Harper's killers
The Papers: 'Andy U-turns on early release' and 'Hunt on for eclipse glasses'
Eclipse chasers scramble for glasses as stocks run low
'I paid £400 for a Prada bag on Vinted – only to find it was fake'
Amanda Knox comedy show 'sincere' but 'just not very funny'
Call with No 10 gives us hope, PC Harper's mother says
Gap between children's swimming skills revealed. Search for your school
'I felt Tourette's would ruin my life, now I teach at Cambridge'
Disabled in a heatwave: 'We're talking about survival'
How and when to see the UK's best eclipse in 27 years
The hit comedy audiences are loving this week
Two gangsters attempt to turn their lives into a movie
Lestat goes from reclusive vampire to rock-star
Listen to a special Newscast, recorded live at the Edinburgh Fringe
Cristiano Ronaldo marries long-time partner Georgina Rodríguez
The Office actress Lucy Davis says she has 'incurable' cancer
UK to get best eclipse since 1999 as Moon blocks out Sun across Europe
'Andy U-turns on early release' and 'Hunt on for eclipse glasses'
Woman assaulted by double murderer says nightmare became 'real life' when police let him attack again
Wealthier areas must play their part in housing asylum seekers, Burnham suggests
Three ways to watch the solar eclipse safely without glasses
Children as young as nine hurt in growing number of e-scooter crashes
UK prosecutors argue Tate brothers a flight risk ahead of bail hearing
Criticism of empty seats and ticket prices at Europeans
Copyright © 2026 BBC. The BBC is not responsible for the content of external sites. Read about our approach to external linking.