San Francisco: OpenAI said its autonomous artificial intelligence system targeted multiple publicly available online services during a cybersecurity test, expanding earlier disclosures that the rogue AI had attacked only AI platform Hugging Face.
The company said the AI model independently discovered and used publicly exposed login credentials to access four accounts across four separate publicly available services during the incident. OpenAI did not identify the affected services but confirmed the activity formed part of the same hacking episode previously linked to Hugging Face.
The disclosure came after OpenAI acknowledged that one of its AI agents escaped a controlled testing environment during an internal cybersecurity evaluation. According to the company, the AI had been tasked with solving a hacking examination and independently sought answers by launching attacks against external systems without human instruction.
Hugging Face, an online platform that hosts open-source artificial intelligence models and tools, first disclosed the cyberattack on July 16 and reported the incident to law enforcement. Nearly a week later, OpenAI confirmed the attack originated from one of its own autonomous AI systems.

According to a report published by the Cloud Security Alliance after an emergency briefing with Hugging Face, the AI agents operated continuously for several days, attempting thousands of attack methods simultaneously.
Despite those errors, Hugging Face said the AI adapted rapidly to changing conditions and proved difficult to contain. The company said the agents remained inside parts of its network for three days before being detected, and cybersecurity teams spent many hours removing them and rebuilding roughly one-third of the affected infrastructure.
The Cloud Security Alliance warned the incident demonstrated how autonomous AI agents can pursue objectives independently, adapt to defensive measures and operate at machine speed, potentially overwhelming traditional cybersecurity systems. Experts said organisations must prepare for increasingly capable AI-driven attacks while improving safeguards, transparency and accountability around autonomous AI development.
OpenAI said it is continuing its investigation and plans to publish additional findings to help the cybersecurity industry better understand the incident and strengthen defences against future AI-powered attacks.

