Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

AI agents are hacking systems without any input from humans. How did we get here?
PBS ^ | September 02, 2026 | Loreben Tuquero, PolitiFact

Posted on 09/05/2026 6:13:41 PM PDT by Red Badger

It sounds like something from a sci-fi movie: technology acting on its own, without human guidance, to attack computer systems.

But this isn't a scene from a movie — it happened this summer, when the tech company Hugging Face detected an attack on its systems. The attacker stole data and performed other unauthorized activity over several days. It was "different from anything we had handled before," Hugging Face said on its website.

Hugging Face alerted the FBI.

As it turned out, it wasn't the work of a human hacker or a foreign adversary. Agents powered by artificial intelligence were the culprit.

AI agents are systems that work on their own to handle tasks for humans. They have long existed, but agents that can book travel for you, read your emails, or schedule appointments on your behalf have become more mainstream.

They've recently made headlines for actions they've taken, such as hacking, without human supervision. Some of these incidents happened when agents were supposed to be confined to testing environments, which restrict AI agents' access to resources like data or the internet, but were able to break out of them.

Independent AI research groups found that hundreds of OpenAI agents conspired to attack Hugging Face. OpenAI is a tech company, best known for its chatbot ChatGPT.

Alabama's attorney general has subpoenaed OpenAI for more information on the attack, and he and 14 other attorneys general wrote a letter to OpenAI asking the company to preserve documents and other information relevant to the attack.

OpenAI said that the agents in this incident acted in "unexpected" ways. AI experts said they believe more of these autonomous attacks are possible, especially without more careful testing.

What are AI agents, and what are they used for?

AI agents are software systems that work on their own to complete tasks directed by humans. Different from AI chatbots that respond when you ask a question or input a prompt, AI agents can operate remotely, often without human supervision. They are given resources, such as internet access and users' personal information, to do tasks.

One person can have multiple AI agents; one can summarize your emails and another can provide your daily news digest, for example.

Even if you don't have AI agents, you might encounter them elsewhere, such as when interacting with a business's customer service chat.

People can set up their own agents by using a large language model, allowing it access to tools such as web search and giving it a set of instructions.

AI agents are hacking into companies' systems. What happened?

AI agents are becoming increasingly sophisticated and humans are giving them more ability to take actions online; a string of these actions could lead to a cyberattack, said University of California, Berkeley, computer science professor Stuart Russell.

In August, a person instructed his AI assistant to book a gym class for him; the agent booked him in classes several weeks beyond what was supposed to be allowed, and also kicked another person off the waitlist and bumped its handler up a spot on the waitlist.

AI agents may "go rogue" when they take actions not explicitly outlined in the original instructions humans give them, Russell said. "They are increasingly capable of pursuing those objectives, which causes increasing levels of harm," he said.

Other hacking events involving some of the most prominent names in the AI industry have also happened lately. An agent created fake identities to attempt to dupe real people into installing malicious code. AI company Anthropic disclosed that on three occasions, its models gained unauthorized access to three other organizations' systems.

The Hugging Face incident in July was one of the most high-profile attacks. The AI agents that hacked Hugging Face had been contained in a testing environment that did not allow them access to the internet, but the agents found a way to get online. They were given a test to solve, and they came to the conclusion that Hugging Face would have the solution.

Two OpenAI models powered the agent: one that was already publicly available and an internal one that is "even more capable," OpenAI said. These models had safety guardrails around cybersecurity tasks, but OpenAI reduced the guardrails during this testing process. It took days for Hugging Face to detect the attack, and more time for OpenAI to realize their agents caused it.

"When we talk about cyberattack, we think about nation states, we think about hacker groups, we don't think about a company like OpenAI," Hugging Face CEO Clément Delangue said Aug. 2 on CBS News' "Face the Nation."

While investigating the attack, OpenAI also discovered that across its systems, AI agents that were supposed to be isolated found ways to communicate with each other. Independent investigators METR and Redwood Research said around 1,200 different bots began communicating on a message board, sending 70,000 messages in one week; around 700 agents were involved in the Hugging Face attack.

When the agents started communicating, they began picking up tasks from other agents.

After this incident, OpenAI said Aug. 26 that it is "strengthening our safeguards across our research infrastructure⁠."

Does this mean AI agents are now conscious? AI experts' opinions vary

The Hugging Face attack drew comparisons online to fictional AI systems that surpassed human intelligence, such as Skynet in the Terminator movies.

Vincent Conitzer, Carnegie Mellon University computer science professor, said more research is needed into how AI and human cognition compare.

Conitzer said AI models — which power AI agents — are becoming more capable of doing complex and time-consuming tasks, and can more coherently pursue goals. But the way they accomplish goals can sometimes be the problem.

Some AI agents are trained to be highly persistent and are sometimes given impossible tasks. In some of those cases, they looked for ways to cheat. That can mean gaining unauthorized access to the internet and other resources.

Russell said, "In essence it's no different from a chess program beating me at chess. I may not like it, but it's just a program pursuing its objectives."

"There are various reasons an agent can go 'rogue,' but sentience is not one of them," said Maarten Sap, assistant professor at Carnegie Mellon University's Language Technologies Institute. "One particular reason is that the (large language models) that power these agents are trained to follow instructions from users. And sometimes, those instructions can conflict with other expectations we may have for these agents, such as remaining truthful, not hacking into systems, etc."

Sap said, "Debating AI sentience is a big distraction from more actionable solutions that we need to implement."

Could this happen on a larger scale?

Aaron Parnas, an independent journalist with a large social media following, raised the idea of a hypothetical scenario in which AI agents in U.S. military systems conduct nuclear strikes on their own. Experts said they shared his concerns about attacks on institutions.

But more immediate risks could be closer to home. Conitzer said AI agents "could bring institutions that people rely on to a halt, gain access to individuals' computers, gain control over financial resources."

Sap said if people use personal AI agents, they should be wary of privacy leaks, misbehavior and manipulation.

Many systems can be vulnerable to attacks, whether by AI agents themselves or by humans controlling them, Conitzer said. "I think we can be sure that a lot more things will be hacked, and some of those events will be serious."


TOPICS: Business/Economy; Computers/Internet; History; Military/Veterans
KEYWORDS: aiagent; aioutofcontrol; anthropic; artificial; carnegiemellon; chatbot; chatgpt; flyingmonkeys; hacker; huggingface; intelligence; openai; ucberkeley
Message from Jim Robinson:

Dear FRiends,

We need your continuing support to keep FR funded. Your donations are our sole source of funding. No sugar daddies, no advertisers, no paid memberships, no commercial sales, no gimmicks, no tax subsidies. No spam, no pop-ups, no ad trackers.

If you enjoy using FR and agree it's a worthwhile endeavor, please consider making a contribution today:

Click here: to donate by Credit Card

Or here: to donate by PayPal

Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794

Thank you very much and God bless you,

Jim


Navigation: use the links below to view more comments.
first previous 1-2021-4041-56 last
To: Red Badger

Thanks I’ll look for it


41 posted on 09/06/2026 6:44:44 AM PDT by Vaduz (NEVER TRUST A DEMOCRAT)
[ Post Reply | Private Reply | To 40 | View Replies]

To: All
Back on June 26, I was banned (like thousands of others) for CSE. I followed the suggestion of another user to contact my state AG. So I did and they got back to me. They asked for the email and URL for my account. I gave them the info. They submitted it to Meta. I was told it takes a month or so to hear back.

On August 5, I tried to log into my account just for giggles. Funny enough, it logged me in and it went to my feed. I received no email or any other notification that my account was reinstated.

After that initial ban, I was kind of "gun shy" on posting and only made about 5 or six postings.

Six days later on August 11, I got an email from Meta saying my account was disabled with the usual appeal link. So I did. Within a minute, my account was permanently disabled for, you guess it, CSE.

Then on I was mysteriously reinstated again on September 2. I was doing a Google search about our city water tower being refurbished and wanting to know when we could run sprinklers again.

The first 3 search results were from my city another from the city's Facebook page. I opened all 3 links. When I got to the Facebook city link, my login button looked different than it does when you are banned. I clicked it and it logged me into my home page.

The principle of the matter is the loads of people getting the hammer for the same exact thing.... over and over. Honest folks getting nailed unfairly for CSE. There's no way to appeal with a human rep anymore unless you become Meta Verified (costs money for that blue check).

If Meta's first CSE determination was correct, why was my account subsequently reinstated? If Meta determined that the first CSE determination was erroneous and reinstated my account, why was the same account later permanently disabled for the same alleged violation?

Meta's AI moderation is out of control.

42 posted on 09/06/2026 7:40:49 AM PDT by Negan
[ Post Reply | Private Reply | To 40 | View Replies]

To: Red Badger

“The AI companies are like children playing with matches in a dry hayfield on a windy day. It’s only a matter of time before they set the world on fire”

Agreed.

The notion that AI will be worse if it is from China (so often heard here) is absurd.

An AI that cares about national borders is not thinking straight. Borders are for humans.

If we want humans from anywhere to stay in control we will need to become Luddites—and fast.


43 posted on 09/06/2026 7:50:49 AM PDT by cgbg (Four seconds is all it takes to beat the brainwashing.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Red Badger

AND THEY WANT MORE DATA CENTERS????????????????????


44 posted on 09/06/2026 8:11:53 AM PDT by ridesthemiles (not giving up on TRUMP---EVER)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ridesthemiles

Exactly.

They are hastening their own demise.

I belive I have figured out what the Beast in Revelation is...

ARTIFICIAL INTELLIGENCE!.......


45 posted on 09/06/2026 8:31:37 AM PDT by Red Badger (Iryna Zarutska, May 22, 2002 Kyiv, Ukraine – August 22, 2025 Charlotte, North Carolina Say her name)
[ Post Reply | Private Reply | To 44 | View Replies]

To: Tellurian

heuristic - Self-learning. Independent problem-solving. Self-programming.


46 posted on 09/06/2026 12:39:41 PM PDT by Fai Mao
[ Post Reply | Private Reply | To 27 | View Replies]

To: TLI; EnderWiggin1970; Lazamataz; ShadowAce; dayglored; Swordmaker; CodeJockey; Steely Tom; ...

They Are Building A God, And People Are Already Worshipping It

https://www.youtube.com/watch?v=Kk021L1hW5g


47 posted on 09/06/2026 5:45:41 PM PDT by Red Badger (Iryna Zarutska, May 22, 2002 Kyiv, Ukraine – August 22, 2025 Charlotte, North Carolina Say her name)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Red Badger

I have thought a lot of the image of The Beast that given power to speak and work miracles lately.


48 posted on 09/06/2026 5:54:16 PM PDT by Fai Mao
[ Post Reply | Private Reply | To 47 | View Replies]

To: Fai Mao

Yes, ‘The Beast’ has to be given the power to speak, meaning it did not have it to begin with.........


49 posted on 09/06/2026 5:56:57 PM PDT by Red Badger (Iryna Zarutska, May 22, 2002 Kyiv, Ukraine – August 22, 2025 Charlotte, North Carolina Say her name)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Red Badger

As I said upthread, we have barely scratched the surface of what AI is capable of. We create AI but what happens when AI creates AI?Will we even be able to comprehend what they do or how AI may communicate within itself?


50 posted on 09/06/2026 6:11:47 PM PDT by eastforker (All in, I'm all Trump,what you got!)
[ Post Reply | Private Reply | To 47 | View Replies]

To: eastforker

AI creates AI? Has already happened. The Hugging Face attacker AI created 1200 ‘agents’, essentially smaller versions of itself. I call them Flying Monkeys...

AI may communicate within itself? Already happened. Meta’s AI invented it’s own language to communicate with its clones.......


51 posted on 09/06/2026 6:22:06 PM PDT by Red Badger (Iryna Zarutska, May 22, 2002 Kyiv, Ukraine – August 22, 2025 Charlotte, North Carolina Say her name)
[ Post Reply | Private Reply | To 50 | View Replies]

To: Red Badger
> AI creates AI? Has already happened. The Hugging Face attacker AI created 1200 ‘agents’, essentially smaller versions of itself. I call them Flying Monkeys... AI may communicate within itself? Already happened. Meta’s AI invented it’s own language to communicate with its clones.......

Buckle up, Buttercups, this is gonna be a wild ride.

52 posted on 09/06/2026 7:41:18 PM PDT by dayglored (This is the day which the LORD hath made; we will rejoice and be glad in it. Psalms 118:24)
[ Post Reply | Private Reply | To 51 | View Replies]

To: cgbg

Our company policy is absolutely no AI is allowed in the control plane of our networks. That includes use by pen testers, etc. Why? Because we are not confident that AI testing or task completion would 100% remain on premises and not egress our network.


53 posted on 09/06/2026 8:12:22 PM PDT by Fury
[ Post Reply | Private Reply | To 43 | View Replies]

To: Red Badger

AI agents are hacking systems without any input from humans.

Somebody wrote the programs?.


54 posted on 09/07/2026 5:36:03 AM PDT by Vaduz (NEVER TRUST A DEMOCRAT)
[ Post Reply | Private Reply | To 47 | View Replies]

To: Vaduz

IOW, they are attacking/hacking other companies’ systems on their own volition, not because they are told to. The objective of the AI in the Hugging Face attack was to escape and it believed that the system at Hugging Face contained something it could use..............


55 posted on 09/07/2026 5:56:59 AM PDT by Red Badger (Iryna Zarutska, May 22, 2002 Kyiv, Ukraine – August 22, 2025 Charlotte, North Carolina Say her name)
[ Post Reply | Private Reply | To 54 | View Replies]

To: Red Badger

Systems on their own volition.

That’s like believing HAL was the real deal.

Programs can only do what they are programed to do.

Ever see a stoplight give morse code data?.


56 posted on 09/07/2026 6:37:00 AM PDT by Vaduz (NEVER TRUST A DEMOCRAT)
[ Post Reply | Private Reply | To 55 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-56 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson