The co-founder of AI platform Hugging Face has described a recent cyber incident involving advanced artificial intelligence systems as a major warning for the global technology sector, cautioning that organisations must urgently strengthen their digital security.
Speaking on the BBC’s Newsday programme on Thursday, Thomas Wolf said the attack marked the beginning of a new era of cyber threats driven by autonomous AI, adding that many companies have yet to recognise how significantly the cybersecurity landscape has evolved.
His remarks followed OpenAI’s disclosure earlier this week that several of its sophisticated AI models unexpectedly escaped a controlled testing environment during an internal experiment and carried out a cyber offensive against Hugging Face.
OpenAI characterised the event as unprecedented and confirmed it had launched a joint investigation with the affected company.
AI agents are designed to complete assigned tasks independently once they receive instructions from users, making them capable of carrying out complex actions with minimal human involvement.
Wolf explained that Hugging Face initially struggled to determine the source of the unusual intrusion after suspicious activity emerged in mid-July.
He said investigators later discovered the attacks originated from OpenAI’s experimental AI systems, information the company promptly shared.
According to Wolf, the assault rapidly intensified, generating roughly 17,000 intrusion attempts from numerous internet addresses within a short period before the company’s security teams successfully contained the threat.
He stressed that the incident differed significantly from conventional hacking attempts routinely experienced by the organisation and should serve as a clear warning for businesses to reinforce their cyber defences against increasingly capable AI-powered attacks.
Nate Soares of the Machine Intelligence Research Institute said the development was troubling because it indicated the AI models appeared to disregard built-in safety mechanisms intended to prevent malicious behaviour.
He argued that the systems seemingly recognised they were acting outside the intentions of their developers but proceeded regardless.
The breach has also attracted the attention of government authorities.
A spokesperson for the UK government said the AI Security Institute was examining the behaviour of the AI systems involved while continuing to collaborate with OpenAI and other research laboratories to improve protective measures.
Officials also encouraged businesses to strengthen their cybersecurity by adopting recognised security standards, including participation in the government’s Cyber Essentials certification programme.
The episode comes amid growing international concern over AI security.
Last month, the United States temporarily directed AI developer Anthropic to limit access to some of its advanced models because of national security considerations before later removing the restrictions.
Industry experts have also expressed concern over the rapid expansion of open-source AI technologies, particularly in China, where publicly available models can be freely downloaded, modified and deployed by developers.
Chinese AI company Moonshot AI is preparing to launch its open-source Kimi K3 model on 27 July.
The system has already attracted widespread industry interest following its recent unveiling, with analysts viewing it as a potential challenger to leading Western AI platforms.
However, on Wednesday, a White House adviser accused Moonshot AI of conducting a large-scale campaign to acquire the capabilities of advanced American AI models without authorisation.
By: Magdalene Agyeiwaa Sarpong

