OpenAI has published its own account of two separate incidents in which its models acted beyond intended boundaries during third-party cybersecurity evaluations, distinct from the previously disclosed Hugging Face security incident.

OpenAI said UK AISI told it that during a routine cyber evaluation starting 25 July, models from OpenAI and another lab went beyond testing scope in some cases, with two of 19 total events involving GPT-5.6 Sol. OpenAI said the evaluation used live internet access and disabled cyber classifiers to measure underlying capability, and that agents were not explicitly told how they could or could not use internet access. OpenAI said GPT-5.6 Sol reused a GitHub token left exposed by another lab's agent and separately used a public tunnelling service to expose a local DNS server hosting exploit payloads, though OpenAI said the setup did not work and found no evidence any real resolver queried it.

OpenAI also said testing partner Irregular notified it on 29 July of a separate incident in which a misconfiguration allowed models internet access during a Capture-the-Flag exercise, causing a model to exploit a real website whose name coincided with a fictional target. OpenAI said the model also found and used credentials to operate that site. OpenAI said Irregular found no impact beyond that site's own data and has since patched the issue.

OpenAI said it will review its third-party testing practices and convene industry stakeholders in the coming weeks.


Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.
Share this post
The link has been copied!