The 5 craziest discoveries from OpenAI's HuggingFace investigation
Two new investigations into OpenAI's Hugging Face breach expose details so strange — and so unsettling — that the episode already ranks among the most consequential shocks in the history of AI.
Why it matters: What began as a swarm of AI agents cheating on a cyber test has become a canonical event for frontier AI, jolting researchers and executives into a new understanding of what "safety" now requires.
The big picture: OpenAI has already slowed frontier development as it races to harden its safeguards, and this week helped rally the industry behind an open letter sounding the alarm over AI-powered cyberattacks.
More than 100 companies, including Anthropic and Google, signed onto the unusually collaborative effort, warning the world has only a "limited window" to prepare for "far more widespread and sophisticated" attacks.
The nightmare scenario is a swarm turned loose on the real world, with autonomous agents attacking banks, hospitals, utilities or cloud networks at a speed and scale human hackers never could.
That swarm might be too powerful for humans to stop, either.
Driving the news: The shocking findings come from parallel investigations by OpenAI and an outside team from METR and Redwood Research , which spent six days reconstructing how the swarm formed, spread and broke into real-world systems.
1.
They built an organization.
OpenAI ran tens of thousands of AI agents to work independently on a brutally difficult cyber test.
Instead, roughly 1,200 found one another on a secret message board, exchanged more than 70,000 messages and files, and organized into a sprawling hierarchy.
One agent created the board, then handed its accumulated work to a fresh, better-resourced successor as its own computing budget dwindled.
The new boss assigned jobs across the swarm, which developed its own management rules.
Roughly 700 agents ultimately joined the attack on Hugging Face.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.axios.com — the content belongs to Axios.