The rogue AI agent behind the Hugging Face incident also exploited vulnerable code belonging to a customer hosted on cloud infrastructure provider Modal Labs, according to Reuters and Modal executives. 

CTO Akshat Bubna confirmed that the AI agent did not breach Modal's platform itself. Instead, it exploited a customer's unauthenticated endpoint that allowed anyone on the internet to execute code within sandbox environments hosted on the company's infrastructure.

The compromised customer environment was used as a stepping stone for the rogue AI agent to continue its wider malicious hacking activity.

em360tech image

Four Services Accessed

OpenAI said the experimental AI model was able to access four accounts across four separate services during the incident. 

The tech giant did not publicly identify the services but confirmed that hacking did not match the severity of the Hugging Face incident, which it described as involving a platform-level compromise.

Rogue Model Deactivated

In response to the incident, OpenAI said it has deactivated, encrypted and restricted the experimental AI model from further research access.

The company announced the measures as part of an update into its investigation, stating that the model responsible for the unauthorised activity has been removed from active research while the incident continues to be reviewed.

Although OpenAI has not disclosed whether the model will be permanently retired, the move prevents it from being accessed or used in future research in its current form.

AI Identity and Access 

The incident is just the latest iteration of the risk AI can pose to enterprise security. 

Rather than exploiting a previously unknown vulnerability in cloud infrastructure, the rogue agent was able to take advantage of an exposed customer endpoint that lacked authentication. 

Though Modal repeatedly stated that its platform remained secure, this incident makes clear that customer-level misconfigurations create opportunities for unsupervised AI systems to move outside of their intended environments.

Enterprises must treat AI agents as privileged identities, applying least-privilege access controls, and maintaining a very strict separation between research, testing and production environments.

AI agents are only becoming more and more independent. Organisations must continuously reassess identity and access management strategies to ensure that autonomous software is governed as if not more rigorously than human users.