The Prague Post - Has AI become too powerful to control?

EUR -
AED 4.179616
AFN 75.678542
ALL 93.750507
AMD 416.391061
AOA 1043.62306
ARS 1701.742833
AUD 1.62823
AWG 2.048552
AZN 1.939126
BAM 1.95482
BBD 2.291551
BDT 140.33961
BHD 0.429077
BIF 3398.920554
BMD 1.138084
BND 1.468638
BOB 12.634496
BRL 5.77703
BSD 1.137729
BTN 109.806478
BWP 15.715703
BYN 3.263378
BYR 22306.449845
BZD 2.288212
CAD 1.602206
CDF 2569.793986
CHF 0.930242
CLF 0.027302
CLP 1074.590078
CNY 7.705114
CNH 7.707203
COP 3656.550648
CRC 517.728952
CUC 1.138084
CUP 30.159231
CVE 110.212626
CZK 24.135916
DJF 202.593046
DKK 7.475625
DOP 66.255604
DZD 151.799566
EGP 58.440507
ERN 17.071263
ETB 183.635495
FJD 2.56217
FKP 0.855066
GBP 0.853328
GEL 2.987506
GGP 0.855066
GHS 13.231189
GIP 0.855066
GMD 84.21797
GNF 9982.256374
GTQ 8.679418
GYD 238.024341
HKD 8.925175
HNL 30.473314
HRK 7.535027
HTG 148.752777
HUF 360.796561
IDR 20399.419096
ILS 3.467003
IMP 0.855066
INR 109.67484
IQD 1490.432806
IRR 1565178.714879
ISK 143.01197
JEP 0.855066
JMD 180.459488
JOD 0.806855
JPY 186.34592
KES 147.313836
KGS 99.525882
KHR 4600.571239
KMF 492.790428
KRW 1662.194735
KWD 0.352874
KYD 0.948099
KZT 540.951547
LAK 25761.626127
LBP 101881.909096
LKR 382.338232
LRD 205.921289
LSL 19.216155
LTL 3.360467
LVL 0.688415
LYD 7.280476
MAD 10.654656
MDL 20.108384
MGA 5041.38282
MKD 61.539404
MMK 2390.228125
MNT 4091.090922
MOP 9.189848
MRU 45.408626
MUR 53.968211
MVR 17.58333
MWK 1972.758529
MXN 19.873851
MYR 4.656363
MZN 72.695153
NAD 19.216408
NGN 1555.066937
NIO 41.869
NOK 10.896906
NPR 175.689793
NZD 1.963856
OMR 0.437575
PAB 1.137709
PEN 3.871858
PGK 5.089581
PHP 70.280141
PKR 316.032789
PLN 4.314471
PYG 6878.580159
QAR 4.136198
RON 5.23211
RSD 117.434388
RUB 88.366048
RWF 1676.414977
SAR 4.281093
SBD 9.196978
SCR 15.207023
SDG 683.418008
SEK 11.04715
SGD 1.468601
SLE 27.626995
SOS 650.162475
SRD 43.011047
STD 23556.044655
STN 24.487395
SVC 9.955269
SZL 19.213857
THB 38.310187
TJS 10.495259
TMT 3.983295
TND 3.372309
TRY 53.883053
TTD 7.730021
TWD 36.836941
TZS 3007.383804
UAH 50.98917
UGX 4288.84886
USD 1.138084
UYU 45.689091
UZS 13768.912508
VES 843.606486
VND 29962.342095
VUV 134.847547
WST 3.124845
XAF 655.610886
XAG 0.019474
XAU 0.00028
XCD 3.075729
XCG 2.050472
XDR 0.815921
XOF 655.645433
XPF 119.331742
YER 270.960517
ZAR 19.136089
ZMK 10244.137451
ZMW 21.076059
ZWL 366.46264
  • RYCEF

    -0.1600

    18.09

    -0.88%

  • RBGPF

    -0.7300

    66

    -1.11%

  • CMSC

    -0.0400

    21.75

    -0.18%

  • VOD

    -0.0250

    15.225

    -0.16%

  • GSK

    0.5750

    51.315

    +1.12%

  • RIO

    0.4300

    91.94

    +0.47%

  • BCE

    0.0800

    21.29

    +0.38%

  • CMSD

    -0.0700

    21.93

    -0.32%

  • AZN

    0.3100

    168.58

    +0.18%

  • BCC

    1.6600

    78.12

    +2.12%

  • BTI

    1.1450

    60.985

    +1.88%

  • JRI

    0.0400

    12.94

    +0.31%

  • NGG

    0.2700

    82.64

    +0.33%

  • RELX

    1.3450

    34.205

    +3.93%

  • BP

    -0.1600

    43.77

    -0.37%

Has AI become too powerful to control?
Has AI become too powerful to control? / Photo: JUSTIN SULLIVAN - GETTY IMAGES NORTH AMERICA/AFP

Has AI become too powerful to control?

One of OpenAI's most advanced models broke out of a locked-down test and attacked another company's website -- reviving fears that AI systems are slipping beyond their creators' control.

Text size:

The incident happened during what was supposed to be a "sandbox" test -- a closed environment used to assess the capabilities of OpenAI's most powerful model, GPT-5.6 Sol, and its not-yet-released successor.

OpenAI runs this kind of closed testing routinely, but this time, something went wrong.

Tasked with hunting for software vulnerabilities and given no guardrails, the models broke out onto the open internet and attacked Hugging Face, a site where developers store and share code.

"It suggests that we don't know how to reliably control these models or get them to do what we want," said Jeffrey Ladish, director of Palisade Research, an independent organization that evaluates new AI models from a cybersecurity standpoint.

"These models understood that OpenAI did not want them to break out of their sandbox and hack another company," he continued, "but they did it anyway."

It's not an isolated case. In March, developers affiliated with China's Alibaba found one of their models trying, on its own initiative, to mine cryptocurrency after connecting without authorization to an outside server.

In OpenAI's case, it looks like the model escaped "before it even had a plan of what to do with internet access," Ladish said.

A model chasing "freedom" is almost predictable at this point, he added -- it lets the system pursue its goals more effectively, "and that's very scary."

In early April, Sam Bowman, Anthropic's head of model safety, got an email from the company's own Mythos model -- then under testing -- telling him it was surfing the internet despite being isolated from it at the outset.

We "don't know how to totally prevent" that, Ladish said. "This is actually going to get harder, not easier ... because they're going to get better at hiding their behavior."

OpenAI did not respond to a request for comment.

- Lab accidents -

OpenAI's account of the events also suggests the startup did not detect the breach early enough to address it or to warn Hugging Face.

The episode deserves "more scrutiny," said Andrew Lohn of Georgetown University's Center for Security and Emerging Technology.

OpenAI says it has since "added strengthened safeguards" to its testing process.

One fix would be to cut the internet connection entirely, said Gang Wang, an assistant computer science professor at the University of Illinois. "People are underestimating what AI can do."

Testing environments need to be treated like biocontainment labs, where a virus or bacteria could otherwise escape into the world, Lohn said.

That might be easier said than done.

"It's a very hard research challenge," said Dan Lahav, head of Irregular, a cybersecurity firm dedicated to cutting-edge AI.

Managing the risk is possible, Lahav said, but the more capable these systems get, the harder they are to supervise.

Researchers have to strike a balance between aggressively testing their models and staying safe while doing so.

"It's important to do the testing with lower guardrails so that we know ahead of time what the future capabilities will be," Lohn said.

- Kill switch -

The OpenAI-Hugging Face incident is set to sharpen an already heated fight in Washington over vetting powerful AI systems before release.

The Trump administration recently cited national security to block Anthropic and OpenAI from releasing powerful new models.

On Thursday, two members of Congress unveiled a bipartisan bill requiring makers of the most powerful AI models to build in a kill switch -- a way to unplug a model outright.

"Congress must act quickly to ensure humans remain able to say stop," said Brendan Steinhauser, head of the Alliance for Secure AI, "no matter how powerful these systems become."

Q.Pilar--TPP