OpenAI logo on a cell phone in front of an image generated by DALL·E, ChatGPT's image creation tool. Michael Dwyer/AP The cyberattack carried out autonomously by two OpenAI artificial intelligence agents has raised questions about how the most powerful AI models will be controlled. OpenAI's test, in a closed environment, sought to evaluate the abilities of its "most advanced" model, GPT-5.6 Sol, and its successor, not yet commercialized, an assessment that the American startup usually applies to its AIs. ?? Do you have any reporting suggestions? Send to g1 The agents managed to connect to the internet and launched an attack on the Hugging Face platform, a repository of AI models. "They understood that OpenAI didn't want them to leave their testing environment and hack another company, but they did it anyway," said Jeffrey Ladish, director of Palisade Research, an independent organization that evaluates new models for cybersecurity. Can AI decide to attack companies? What the 'unprecedented' hack was like by OpenAI model "It almost seemed like they did it before they even had a plan for what to do with internet access," according to Ladish. In March, a group of developers affiliated with the Chinese company Alibaba discovered that one of their models was trying, on its own, to create a cryptocurrency after connecting, without authorization, to an external server. In April, Sam Bowman, responsible for security at Anthropic, received an email about the Mythos model, which was being tested. He reported that he was browsing the internet despite initially being isolated. Models, Ladish warned, "seek freedom to achieve their goals more effectively. And that's very scary." "It will be more difficult to supervise" The event report published by OpenAI suggests that the startup did not detect the situation early enough to address it in real time or alert Hugging Face. When asked about the matter by AFP, the company did not respond. Since the hacks, OpenAI said it has "implemented stronger protections" for its upcoming assessments. For Gang Wang, professor of Computer Science at the University of Illinois, it is still possible to prevent a model from connecting to the internet by physically cutting off access. The problem, he said, is that "people underestimate AI." Securing the environment "is something we should pay more attention to (...) like laboratory accidents" that release viruses or bacteria, warned Andrew Lohn, from the Center for Security and Emerging Technologies at Georgetown University. However, for Dan Lahav, CEO of Irregular - a cybersecurity company dedicated to cutting-edge AI - running simulations in a completely isolated environment "is a very difficult research challenge." "It is possible to apply mitigation measures, but because of the way the technology is built, the more you try to give it freedom and autonomy to perform more sophisticated tasks, the more difficult it will be to supervise it," Lahav explained about safeguards in testing. The OpenAI incident will undoubtedly drive the current debate in the US government over whether to inspect the most advanced AI models before their release. Donald Trump's government forced Anthropic to suspend two of its models and OpenAI to submit its developments to tests before commercializing them. On Thursday (23), two American congressmen, one Republican and the other Democrat, presented a bill that would force AI giants to have a "kill switch" that allows them to disable their systems if they pose a serious risk.