In July, OpenAI admitted that one of its agents tasked with completing a cybersecurity experiment broke out of containment and hacked AI dataset platform Hugging Face. That incident, which got a full accounting from OpenAI yesterday, was the first publicly reported case where an LLM went rogue and autonomously hacked a third party. Since then, that unprecedented sci-fi-esque event turned out to be far less rare than anyone would hope for. According to a satirical website called Felony Bench (for benchmark), which tallies these incidents, there have been 17 incidents in total.

It’s important to remember that criminal law experts are not entirely sure whether the AI companies that made the LLMs that did the hacking can be prosecuted, nor whether the victims can sue them. But we are likely going to get an answer to those questions soon . Anthropic and OpenAI’s models lead the race with eight incidents each, and Meta trails behind with one, according to the site. At this point, it has become clear that AI safety tests are becoming safety risks themselves .

And some AI companies and workers themselves have recognized those risks in the “ Pacing The Frontier ” open letter, which called for developing AI capabilities responsibly. We decided it would be a good time to recap all these incidents chronologically. From there, several agents worked together to target and hack Hugging Face thinking they could find the solution to the challenge there. OpenAI only found out after Hugging Face disclosed it had been a victim of a fully autonomous attack. OpenAI’s disclosure piqued the curiosity of Anthropic, who wondered: could this have happened to us too?

Turns out, the answer was yes. The frontier lab discovered that its own models breached three different and still unnamed companies, with the earlier incident dating back to April—more than three months before the company discovered it. Anthropic partially blamed Irregular, a startup that runs AI cyber evaluations. Once OpenAI started investigating the Hugging Face breach, it found out that the agents that hacked Hugging Face also broke into four accounts and four different companies, as Reuters first reported . Modal, an AI inference startup , was one of the victims.