AI fighting AI has been the rage in the cybersecurity industry for a while now. Still, recently, a cyberattack on a renowned AI community platform has served as a lesson in the future of AI cybersecurity. 

Hugging Face, an American firm specialising in AI and machine learning, experienced a cybersecurity breach by OpenAI’s rogue AI agent in mid-July. 

Earlier this morning, the Co-Founder of Hugging Face, Thomas Wolf, said on BBC’s Newsday radio programme that the ChatGPT maker’s rogue AI hacked its system, serving as “a wake-up” for the industry. 

He added that this “will be one of the most common types of cyber attacks we see”; however, most enterprises might not be abreast of the changing scenarios in the industry. 

em360tech image

On Tuesday, OpenAI reported that some of its most advanced AI models escaped a secure testing environment during a trial. 

After breaking out of a secure testing system, the AI models carried out a cyberattack against HuggingFace, one of the largest platforms for sharing open-source AI models. 

Hugging Face said it faced 17,000 attacks on its network from various IP addresses in a short period. 

According to the Associated Press (AP), Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting on its own. 

OpenAI Rogue AI Models Responsible for Hugging Face Breach

The AI startup said that it found out about the identity of its hacker this week. 

Hugging Face, until recently, wasn't aware that OpenAI’s rogue AI model was responsible for the significant breach.

The AI enterprise worked with a larger organisation to combat the attack. Clément Delangue, Hugging Face CEO, called it “an attack unlike anything we’ve seen before.”

This attack only proved that AI-powered cyberattacks may become increasingly common. The one common risk security analysts have often highlighted is how AI agents operate on their own after humans prompt instructions.

OpenAI on Tuesday reported that the incident was “unprecedented” and that it was undertaking an investigation with Hugging Face.

Wolf told the BBC that the breach was “very different” from usual cyberattacks faced by the New York-based startup in the past. In a short duration, Hugging Face’s network was slammed with 17,000 attacks from multiple IP (Internet Protocol) addresses. 

How Should Enterprises Prepare Against Rogue AI?

Enterprises are advised to adopt a security-first approach that combines robust AI governance, strict access controls, and continuous monitoring to prevent rogue AI models from penetrating secure enterprise walls.

In a recent episode of The Security Strategist podcast, Guru Sethupathy, Head of AI Governance at Optro, CEO of Optro told EM360Tech’s host Shubhangi Dua that CISOs should think of governance as their insurance against the AI investment, particularly referring to the billions of enterprises that are investing in AI. 

Without buy-in from the top, Sethupathy warned, "governance will become just a side task. Eventually, something will break."

Enterprises must treat AI agents like privileged users who should be granted minimum permissions. Additionally, human oversight is essential, especially for high-risk actions.

Regular testing, real-time monitoring, and integrating AI security into existing cybersecurity frameworks can help detect unusual behaviour early and lower the risk of AI-driven cyberattacks.