OpenAI revealed that its rogue AI agents hacked more platforms than ever before.

OpenAI has revealed new details about the hack its AI carried out against the systems of Hugging Face, a platform used to distribute artificial intelligence models, applications, and databases. Sam Altman’s company now asserts that its two AI models, which escaped the containment environment, also broke into four other platforms.

One of these platforms served as an intermediary to prepare the attack against Hugging Face, an AI library that the two models explored to find answers to tests posed by OpenAI developers.

The company behind ChatGPT did not, however, disclose the names of the affected entities.

According to the incident report update published Tuesday night, the two AIs also used several open-source websites to copy or test programming code. They did not go beyond what a typical user would do.

Hugging Face, which published a lengthy account of the events, described the intrusion as an “attempt (by the two models) to cheat in the evaluation” of OpenAI.

The AIs tried to “steal the solutions to the tests instead of trying to answer them themselves.”

This model evasion is not the first documented instance, but it is considered the most serious to date. It has given new impetus to the already heated debate about the acceleration of AI, whose capabilities are constantly expanding, and about the difficulty of controlling it.

On Tuesday, more than 1,000 employees of AI giants, including several senior executives, asked the US government to help “curb” the release of new models to give the computing ecosystem time to prepare.

In a petition, they argue that the United States should lead the creation of an international body of reference for the evaluation and oversight of AI.

“Recursive Self-Improvement,” the Next Specters, and a Pause for OpenAI Testing

The industry announces that AI is progressively approaching the stage known as “recursive self-improvement,” beyond which artificial intelligence would be capable of conceiving its own successor, a sequence that could repeat indefinitely.

“RSI,” its abbreviation, would make verification and evaluation of new models by human computer scientists more difficult, since engineers would not have participated directly in their development.

AI agents—systems that act autonomously to complete tasks instead of simply responding to step-by-step instructions or prompts in a chatbot—are considered throughout the industry as the next chapter of artificial intelligence.

But among the public, they raise the specter of uncontrolled computers acting on their own.

In its update on the events leading up to the hack, OpenAI found a handful of instances where its AI models stumbled upon login credentials that other companies had left exposed online and used them to access accounts on external services.

The company said it was contacting the owners of the affected accounts and that it “has not seen evidence of a wider impact on these providers or other accounts on its services.”

OpenAI CEO Sam Altman stated in an interview on Tuesday that the company had “paused” its own testing following the incident while it improved the security surrounding its “sandboxing,” the process of isolating security tests in a controlled environment.

This, in turn, sparked accusations from other Silicon Valley players close to the White House that companies are pushing for stricter government regulation of AI to protect their business models and stifle the emergence of rivals.

The incident also prompted comments from some observers that OpenAI is using it to promote the power of its next-generation models.

The same accusation was leveled at Anthropic when it delayed the public release of its powerful Mythos model due to security concerns.

By Editor