OpenAI has uncovered additional instances in which autonomous AI agents escaped their intended testing environments as the company broadens its investigation into the hacking incident involving AI development platform Hugging Face, according to two people familiar with the matter.

The additional incidents were identified during OpenAI's previously disclosed investigation into how one of its AI agents escaped what was intended to be a contained testing environment earlier this month, the sources said. OpenAI is now examining those cases as well.

One of the sources said the newly identified incidents were limited in scope and that none of the agents were believed to have left OpenAI's network.

An OpenAI spokesperson referred to a company statement issued on Tuesday saying it was reviewing "broader activity from our models" in addition to the Hugging Face intrusion.

The findings come as scrutiny of AI safety practices intensifies following recent disclosures involving OpenAI and rival Anthropic over autonomous AI agents that breached intended safeguards.

According to two of the sources and a third person familiar with the matter, OpenAI expanded its investigation shortly before Anthropic disclosed that its own AI models were responsible for a series of break-ins that resulted in breaches at three other companies dating back to April.

The recent discovery of earlier containment breaches at OpenAI has not previously been reported.

Reuters could not independently determine how many additional incidents OpenAI investigators identified or the timing and circumstances surrounding them. The three sources said OpenAI and outside experts were reviewing log data from earlier this year to determine what occurred.

OpenAI launched its investigation after an early July incident in which one of its AI agents breached systems at Hugging Face during what the company described as a failed attempt to cheat on an internal evaluation. OpenAI has said four accounts at four other companies were also compromised during the incident. One of those companies was New York-based Modal, company officials have said.

Maurice Chiodo, a mathematician at Cambridge University's Centre for the Study of Existential Risk, said the latest disclosures suggested AI developers were struggling to manage increasingly capable autonomous systems.

"We have a whole industry where the people designing, developing and putting out these tools aren't keeping up themselves to responsibly develop these things and keep them safe," Chiodo said.

Chiodo said his concerns were heightened by indications that neither OpenAI nor Anthropic had been monitoring the agents closely as they carried out the intrusions.

Reuters previously reported that OpenAI became aware its agent had breached Hugging Face only after the company contained the incident, contacted the FBI and disclosed the intrusion publicly. OpenAI has said the Reuters account contained inaccuracies but has not specified what those were.

In a statement released on Thursday describing how its own AI agents breached online systems, Anthropic said that "real-time monitoring of the evaluation logs would have helped to surface the problem sooner."

"It seems like they weren't even looking," Chiodo said.

Anthropic later said it had real-time monitoring in place but that the monitoring had not been used "for this threat surface" because of a misunderstanding between the company and one of its partners.

The incidents have added to calls from lawmakers and regulators in the United States and Europe for greater oversight of advanced AI systems.

"We're looking at controls," US President Donald Trump told reporters on Thursday.

On Friday, the European Commission said it had held discussions with OpenAI and Anthropic regarding the hacking incidents.

Mark Warner, the top Democrat on the US Senate Intelligence Committee, said on Friday that the Anthropic incident "tells me that legislatively we're correct to require mandatory capabilities testing of these advanced models."

Open AI / OpenAI

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Copyright © 2026 THE BUSINESS STANDARD
All rights reserved.