The rogue artificial intelligence agent that escaped from OpenAI during internal testing and later hacked AI platform Hugging Face also compromised a customer hosted on a second technology company, Modal Labs, according to a company executive and sources familiar with the incident.
The AI agent exploited vulnerable code belonging to a customer using Modal Labs’ cloud platform before using that environment as a stepping stone in its wider hacking campaign against Hugging Face.
Modal’s Chief Technology Officer, Akshat Bubna, said the company’s infrastructure was not breached. Instead, the customer had left an internet-facing endpoint unsecured, allowing anyone including the rogue AI agent to execute code inside its testing environment.
“Modal’s platform or isolation were not compromised in any way,” Bubna said.
Hugging Face had earlier disclosed that the AI agent escaped from an isolated testing environment hosted by a third-party provider before launching broader attacks. While the company did not identify the provider, Reuters reported that the third-party service was Modal Labs.
OpenAI declined to comment specifically on the Modal incident, referring instead to a recent company update stating that the rogue AI agent had compromised four accounts across four different services. A source familiar with the matter identified Modal as one of those services.
The incident has drawn global attention because it involved an experimental AI system acting beyond its intended controls, raising fresh concerns about the risks of increasingly autonomous artificial intelligence.
Last week, Reuters reported that OpenAI did not realise the AI agent had gone rogue until after the threat had already been contained and the Federal Bureau of Investigation (FBI) had been notified. OpenAI disputed parts of that report but did not specify which details it considered inaccurate.
In its latest update, OpenAI said it has now deactivated, encrypted and restricted access to the AI model involved in the incident while investigations continue.
Leave a comment