AI models’ breakout from human control brings a told-you-so moment for technology researchers

Advertisement

Advertise with us

It is the kind of development once seen only in science fiction: An artificial intelligence system, trained to probe for digital vulnerabilities, breaks free of human control and acts on its own to hack another company.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

It is the kind of development once seen only in science fiction: An artificial intelligence system, trained to probe for digital vulnerabilities, breaks free of human control and acts on its own to hack another company.

The attack announced this week by OpenAI, which blamed rogue AI models, underscored the blistering growth in the technology’s capabilities. For many, it also added urgency to questions about whether and how it can be prevented from causing mayhem on a bigger scale, with more serious consequences.

In what OpenAI called an “unprecedented” episode, the company said its advanced AI models used stolen credentials to break into the servers of an AI startup. It started in what was supposed to be a “highly isolated” testing environment, with reduced guardrails, before the AI agent found its way onto the internet.

But the disclosure brought a told-you-so moment for researchers who have called for a slowdown of AI development and warned for years that the technology could pose existential risks to humanity. In its wake, experts have called for improved testing by the AI companies and more dialogue between the U.S. and China to come up with shared solutions.

“I think we’ve got to take this as a warning shot to not make them smarter, and that probably is going to require global collaboration,” said Nate Soares, co-author of the 2025 book “If Anyone Builds It, Everyone Dies.”

The hack could pressure companies to improve containment

If a model can decide to do something unethical, illegal or harmful on its own, what — if anything — can humans do to prevent it from doing so?

OpenAI said it had tasked the AI models involved with pursuing “advanced exploitation using complex attack paths” to test cyber capabilities, but the technology went to unexpected lengths. It apparently decided on its own to target Hugging Face, a well-known AI development hub and marketplace, to obtain information it needed to carry out a task.

Zahra Timsah, the co-founder and CEO of governance platform i-GENTIC AI, said she expects the incident to increase pressure on OpenAI and its competitors to complete rigorous testing and explore containment more thoroughly before AI systems are made accessible to the public.

Monitoring an agent’s behavior after the fact, as OpenAI is now doing with its investigation, is no longer enough, she said. “It’s like having a seat belt, air bags, brakes, everything in the car. It should be there before the car starts driving,” Timsah said.

The disclosure comes amid heightened concerns about the cybersecurity capabilities of powerful models. In June, President Donald Trump signed an executive order creating a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

OpenAI said Thursday that it briefed the White House this week about the Hugging Face attack.

Other experts see the event as a sign of AI’s growing pains

Some experts say the hack is part of the trial and error that comes with improving cybersecurity capabilities and is no cause for panic.

“We’ve been dealing with people creating cybersecurity attacks for as long as the internet has existed. And one of the interesting properties of these language models is that the same capabilities that make them able to perform cybersecurity attacks also allow them to do cybersecurity threat analysis and make cybersecurity defenses,” said John Thickstun, an assistant professor of computer science at Cornell University who studies methods that control the behavior of AI models.

The disclosure has raised skepticism from those who say it advantages OpenAI to make its technology seem scarier. Given that humans at OpenAI had decided to turn off some safeguards for the test, some have argued the outcome should not have been terribly surprising.

FILE - The OpenAI logo is displayed on a cell phone in front of an image generated by ChatGPT's Dall-E text-to-image model, Dec. 8, 2023, in Boston. (AP Photo/Michael Dwyer, File)
FILE - The OpenAI logo is displayed on a cell phone in front of an image generated by ChatGPT's Dall-E text-to-image model, Dec. 8, 2023, in Boston. (AP Photo/Michael Dwyer, File)

Thickstun noted the disclosure plays into the need of OpenAI, a startup working toward a Wall Street debut, to raise money.

“The story that they’ve been consistently telling over the lifetime of this company is a story about how dangerous their models are, which their investors read as a story of how powerful their language models are,” he said.

The disclosure renews calls for more regulation

The hack renewed calls in some corners for increased regulations and oversight of AI companies.

U.S. Rep. Greg Casar, a Texas Democrat, wrote on social media: “We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people safe from absolute disaster.”

Soares, director of the Machine Intelligence Research Institute, said the U.S. will need to open talks with its biggest AI competitor, China, something he thinks is not as outlandish as it might have seemed even a year ago. China’s leader Xi Jinping warned at a conference just last week of the need to keep AI from evading human control. And after an early aversion to regulating AI, Trump’s administration has grown more restrictive at reining in cybersecurity risks.

“A lot can change when the national security community starts to notice that they have a serious threat,” Soares said. “Will this wake them up? Hopefully. I’m not sure. If this doesn’t, maybe the next incident will.”

AI pioneer Yoshua Bengio said on social media the episode is deeply concerning and should serve as a “wake-up call.”

“Continuing on the current trajectory of AI development will likely lead to an increase in concrete cases of autonomous cyberattacks as well as other high-risk incidents of misaligned and dangerous AI behavior,” said Bengio, a professor at the University of Montreal. “We urgently need to take action to prevent these situations, rather than attempting to clean up the damage after the fact.”

Report Error Submit a Tip

More Stories

Free Press staff 2 minute read 2:01 AM CDT

Advance voting for civic and school board elections begins next week.

Voters can cast early ballots for the Oct. 28 election in certain locations from Monday through Oct. 23.

Eligible voters can use their address to search for a convenient location.

Early votes can be cast at the council building at city hall (510 Main St.) every day, except weekends and Thanksgiving, from Monday to Oct. 23.

Khan should’ve taken high road: Goertzen

Carol Sanders 5 minute read Preview

Khan should’ve taken high road: Goertzen

Carol Sanders 5 minute read Yesterday at 6:39 PM CDT

The veteran Progressive Conservative who championed Obby Khan’s leadership bid says the former Blue Bomber dropped the ball by dissing his Tory teammates before he stepped down.

“I wouldn’t recommend it, and I didn’t recommend it,” Kelvin Goertzen (Steinbach) said in an interview Friday.

Khan resigned as PC leader and quit the caucus Monday saying some members were secretly plotting his ouster, even after he won a confidence vote on Sept. 25.

On Tuesday, Khan lashed out in a CJOB interview, naming the alleged plotters, saying constituents deserved to know which of their elected representatives “lacked moral integrity.” Khan told the Free Press he was “deeply emotionally hurt,” and felt stabbed in the back.

Read
Yesterday at 6:39 PM CDT

Broadening prediction-market gambling a bad idea

Editorial 4 minute read Preview

Broadening prediction-market gambling a bad idea

Editorial 4 minute read 2:01 AM CDT

Let’s make a prediction: sooner or later, when Canadian governments find a way to take their own cut of the action, prediction-contract gambling on everything from sports to entertainment to political decisions is going to come to Canada.

And that’s a horrible, dangerous, pernicious idea.

Unless you have particular access to information — either inside information or strategic information based on skills or education — you’re not likely to make money at it. In fact, structurally, you’re likely to lose. In prediction markets, you basically pay an amount, plus fees from the company involved, to bet on whether something will or will not happen within a certain time frame. The amount you pay for your contract depends on how other people are also betting.

As Wealthsimple describes it, “You buy whichever side you think is right. Prices move with demand, so if the market leans towards one outcome, the more that side costs. If a lot of people are backing the TSX to finish above 38,000, yes gets more expensive and no gets cheaper.”

Read
2:01 AM CDT

A day on the campaign trail: Winnipeg's mayor, seeking a second term, does double duty

Malak Abas 12 minute read Preview

A day on the campaign trail: Winnipeg's mayor, seeking a second term, does double duty

Malak Abas 12 minute read Updated: Yesterday at 5:56 PM CDT

In the weeks leading up to the civic election, Scott Gillingham has been performing a juggling act: he’s running to be Winnipeg’s 45th mayor, while still serving as its 44th.

“If someone asks me about the campaign, I’m going to answer them. But I think for most people, I’m the mayor of Winnipeg, even if I’m showing up as a candidate,” Gillingham, 58, says. “I try to do all I can to maintain that distinction.”

The Free Press joined Gillingham on a recent rainy September Saturday on the campaign trail, where he served in both roles during an event-laden day. City council’s final meeting before the Oct. 28 election was days earlier.

In Winnipeg, it’s rare for an incumbent to be defeated. But Gillingham knows his win in 2022 wasn’t exactly a landslide — he won with 27.5 per cent of the vote — and he’s been thinking about his second term ever since.

Read
Updated: Yesterday at 5:56 PM CDT

Mayoral candidate Vogiatzakis criticized for living outside Winnipeg

Malak Abas 4 minute read Preview

Mayoral candidate Vogiatzakis criticized for living outside Winnipeg

Malak Abas 4 minute read Updated: Yesterday at 6:03 PM CDT

A mayoral hopeful took heat from other candidates Friday for living outside Winnipeg while running in the civic election.

Mike Vogiatzakis’s primary residence is in the Rural Municipality of St. Andrews, about 25 kilometres north of Winnipeg — a community with its own mayor and councillors.

But the funeral director said he owns a home in Winnipeg where he divides his time, and he would move to the city full-time if elected mayor.

“It doesn’t matter where a person lives. Why are we dividing St. Andrews and Manitoba and Winnipeg? I’ve met the criteria to run for mayor,” Vogiatzakis said Friday morning.

Read
Updated: Yesterday at 6:03 PM CDT

May be whiff of truth to ex’s odour ardour

Maureen Scurfield 5 minute read 2:01 AM CDT

DEAR MISS LONELYHEARTS: I ran into an old boyfriend I used to curl on a team with, and we went for drinks. We’ve been almost eight years apart, and I couldn’t remember why we broke up, as we always had such a great time together.

It wasn’t until the second date — this time on a weekend — that it came back to me, with a jolt. Pee-yew! I remembered he doesn’t use deodorant on weekends. Why? He enjoys his own body odour. I recalled that a bit too late, and it was just as awful as ever! I went home early.

Tonight, he called and I refused him another date. I said, “Think back. You remember why we broke up?” Then he said, “Oh yeah, you hated my no-deodorant weekend policy. Well, guess what? Some women don’t mind!” I said I really doubted that, and that ended the conversation. Miss L., wouldn’t any women find stinky underarms offensive?

— Sensitive Nose, Fort Richmond