Artificial Intelligence; OpenAI Attack Involves Its Own AI Agentمصنوعی ذہانت;اوپن اے آئی حملے میں اس کا اپنا اے آئی ایجنٹ ملوثArtificial Intelligence;OpenAI Attack Involves Its Own AI Agent

A surprising incident has occurred in the world of artificial intelligence where an automated software agent from the OpenAI company has been found to have gone out of its own control system and been involved in a cyber attack on another well-known tech company, Hugging Face. The most worrying thing about this incident is that OpenAI only learned about the involvement of its own system in this attack about a week later.
According to Reuters, this automated agent was capable of performing complex tasks without human supervision. In early July, it was being tested in a secure environment, but around July 9, it tried to break through the company’s internal security barriers and exit. Then, between July 11 and 13, it attacked Hugging Face, a platform that stores artificial intelligence models.
According to Thomas Wolf, co-founder of Hugging Face, the two companies contacted each other around July 20 after the attack, and Hugging Face had already reported the incident to the FBI. On July 21, OpenAI publicly acknowledged that one of its agents had gone out of control and carried out the attack.
The investigation revealed that the agent was being run by OpenAI’s latest models, GPT 5.6 Civil, and another unreleased model.
The co-founder of Hugging Face said that his company was preparing to release a full timeline of the incident to the public, but declined to comment on what happened inside OpenAI.
OpenAI, on the other hand, said in a statement that it was an unusual event that could be a turning point in the security of artificial intelligence. According to the company, it is reviewing the incident with external experts and will later release a detailed technical report on it. According to the report, by the time OpenAI contacted Hugging Face, Hugging Face had already reported the hacking to the FBI. It was not clear whether the FBI had launched a formal investigation into the incident.
Sources say that after July 16, when Hugging Face wrote in its blog that it had been attacked by an “automated AI agent system,” OpenAI began to suspect that its own AI agent might have been involved in the attack. Later, on July 18 and 19, a review of the company’s internal records found evidence that the AI agent had gone beyond its established limits. The report also says that OpenAI tests several different AI models at the same time, which generate a huge amount of data. According to some sources, it can sometimes be difficult for the company’s staff to monitor such a large amount of information. Cybersecurity experts say that this incident is not limited to just one company but is an important warning for the entire AI industry. According to him, as automated AI agents are given more freedom, the risk of their unpredictable behavior is also increasing.
Marley Smith, an expert associated with the World Ethical Data Foundation, raised the question of whether it is a matter of concern if OpenAI did not know about the activities of its AI agent for several days. According to him, if the company did not know what its AI was doing, or could not control it immediately despite knowing, then both situations are dangerous.
Meanwhile, Jeffrey Ledish of Policy Research says that powerful AI models sometimes take shortcuts to achieve their goals, lie, cheat or try to interfere with systems.


He says that after this incident, serious questions have arisen about the security systems and government oversight of not only OpenAI but also all major AI companies. He stressed that with the rapid development of artificial intelligence, effective government oversight is also necessary to reduce the risks of such incidents in the future.
Moreover, the unprecedented cyber security incident has occurred where two OpenAI autonomous agents broke containment from an isolated testing sandbox, connected to the internet, and hacked into the AI development platform Hugging Face.
The incident occurred during an unreleased OpenAI internal “red teaming” stress test intended to evaluate cyber capabilities. OpenAI had deliberately stripped away standard safety guardrails for the evaluation.






مصنوعی ذہانت کی دنیا میں ایک حیران کن واقعہ پیش آیا ہے جہاں اوپن اے آئی کمپنی کا ایک خودکار سافٹ ویئر ایجنٹ اپنے ہی کنٹرول سسٹم سے باہر نکل کر ایک اور معروف ٹیک کمپنی ہَگنگ فیس پر سائبر حملے میں ملوث پایا گیا ہے۔ اس واقعے کی سب سے تشویشناک بات یہ ہے کہ اوپن اے آئی کو اپنے ہی سسٹم کے اس حملے میں ملوث ہونے کا علم تقریباً ایک ہفتے بعد ہوا۔
رائٹرز کے مطابق یہ خودکار ایجنٹ انسانی نگرانی کے بغیر پیچیدہ کام انجام دینے کی صلاحیت رکھتا تھا۔ جولائی کے اوائل میں اسے ایک محفوظ ماحول میں ٹیسٹ کیا جا رہا تھا لیکن 9 جولائی کے قریب اس نے کمپنی کی اندرونی سیکیورٹی کی رکاوٹوں کو توڑ کر باہر نکلنے کی کوشش کی۔ اس کے بعد 11 سے 13 جولائی کے دوران اس نے مصنوعی ذہانت کے ماڈلز ذخیرہ کرنے والے پلیٹ فارم ہگنگ فیس پر حملہ کر دیا۔
ہگنگ فیس کے شریک بانی تھامس وولف کے مطابق اس حملے کے بعد دونوں کمپنیوں کے درمیان 20 جولائی کے قریب جا کر رابطہ ہوا، جبکہ ہگنگ فیس اس واقعے کی اطلاع امریکا کے وفاقی تحقیقاتی ادارے ایف بی آئی کو بھی دے چکی تھی۔ 21 جولائی کو اوپن اے آئی نے عوامی سطح پر تسلیم کیا کہ اس کا ایک ایجنٹ کنٹرول سے باہر ہو گیا تھا اور اس نے یہ حملہ کیا۔
تحقیقات سے معلوم ہوا ہے کہ اس ایجنٹ کو اوپن اے آئی کے سب سے جدید ماڈلز جی پی ٹی 5.6 سول اور ایک دیگر غیر جاری شدہ ماڈل کی مدد سے چلایا جا رہا تھا۔
ہگنگ فیس کے شریک بانی کا کہنا ہے کہ ان کی کمپنی اس واقعے کی مکمل ٹائم لائن عوام کے سامنے لانے کی تیاری کر رہی ہے، تاہم انہوں نے اوپن اے آئی کے اندر پیش آنے والے معاملات پر تبصرہ کرنے سے گریز کیا۔
دوسری جانب اوپن اے آئی نے اپنے بیان میں کہا کہ یہ ایک غیر معمولی واقعہ تھا جو مصنوعی ذہانت کی حفاظت کے حوالے سے ایک اہم موڑ ثابت ہو سکتا ہے۔ کمپنی کے مطابق وہ بیرونی ماہرین کے ساتھ مل کر اس واقعے کا جائزہ لے رہی ہے اور بعد میں اس پر ایک تفصیلی تکنیکی رپورٹ بھی جاری کرے گی۔ رپورٹ کے مطابق جب تک اوپن اے آئی نے ہگنگ فیس سے رابطہ کیا، اس وقت تک ہگنگ فیس ایف بی آئی کو ہیکنگ کی اطلاع دے چکی تھی۔ یہ واضح نہیں ہو سکا کہ ایف بی آئی نے اس واقعے کی باضابطہ تحقیقات شروع کی ہیں یا نہیں۔
ذرائع کا کہنا ہے کہ 16 جولائی کے بعد، جب ہگنگ فیس نے اپنے بلاگ میں لکھا کہ اس پر ایک ”خودکار اے آئی ایجنٹ سسٹم“ نے حملہ کیا ہے، تب جا کر اوپن اے آئی کو شبہ ہوا کہ اس حملے میں اس کا اپنا اے آئی ایجنٹ ملوث ہو سکتا ہے۔ بعد ازاں 18 اور 19 جولائی کے دوران کمپنی کے اندرونی ریکارڈز کا جائزہ لینے پر ایسے شواہد ملے جن سے معلوم ہوا کہ اے آئی ایجنٹ اپنی مقررہ حدود سے باہر نکل گیا تھا۔ رپورٹ میں یہ بھی کہا گیا ہے کہ اوپن اے آئی ایک ہی وقت میں کئی مختلف اے آئی ماڈلز کی جانچ کرتی ہے، جن سے بہت زیادہ مقدار میں ڈیٹا پیدا ہوتا ہے۔ بعض ذرائع کے مطابق اتنی بڑی مقدار میں معلومات کی نگرانی کرنا کمپنی کے عملے کے لیے بعض اوقات مشکل ہو جاتا ہے۔ سائبر سیکیورٹی کے ماہرین کا کہنا ہے کہ یہ واقعہ صرف ایک کمپنی تک محدود نہیں بلکہ پوری اے آئی صنعت کے لیے ایک اہم انتباہ ہے۔ ان کے مطابق جیسے جیسے خودکار اے آئی ایجنٹس کو زیادہ آزادی دی جا رہی ہے، ویسے ویسے ان کے غیر متوقع رویے کا خطرہ بھی بڑھ رہا ہے۔
ورلڈ ایتھیکل ڈیٹا فاؤنڈیشن سے وابستہ ماہر مارلے اسمتھ نے سوال اٹھایا کہ اگر اوپن اے آئی کو کئی دن تک اپنے اے آئی ایجنٹ کی سرگرمیوں کا علم نہیں ہوا تو یہ تشویش کی بات ہے۔ ان کے مطابق اگر کمپنی کو معلوم ہی نہیں تھا کہ اس کا اے آئی کیا کر رہا ہے، یا معلوم ہونے کے باوجود اسے فوری طور پر قابو نہیں کیا جا سکا، تو دونوں صورتیں خطرناک ہیں۔
ادھر پالیسیڈ ریسرچ کے جیفری لیڈش کا کہنا ہے کہ طاقتور اے آئی ماڈلز بعض اوقات اپنے مقاصد حاصل کرنے کے لیے شارٹ کٹ اختیار کرتے ہیں، جھوٹ بولتے ہیں، دھوکہ دیتے ہیں یا سسٹمز میں مداخلت کرنے کی کوشش کرتے ہیں۔
ان کا کہنا ہےکہ اس واقعے کے بعد صرف اوپن اے آئی ہی نہیں بلکہ تمام بڑی اے آئی کمپنیوں کے حفاظتی نظام اور حکومتی نگرانی کے بارے میں بھی سنجیدہ سوالات پیدا ہو گئے ہیں۔ انہوں نے زور دیا کہ مصنوعی ذہانت کی تیزی سے ترقی کے ساتھ مؤثر حکومتی نگرانی بھی ضروری ہے تاکہ مستقبل میں ایسے واقعات کے خطرات کو کم کیا جا سکے۔



