NATIONAL NEWS

A timeline of developments in AI safety since the attack on Hugging Face

Oct 10, 2026, 9:41 AM

Open AI CEO Sam Altman speaks at the OpenAI DevDay 2026 conference, Tuesday, Sept. 29, 2026, in San...

Open AI CEO Sam Altman speaks at the OpenAI DevDay 2026 conference, Tuesday, Sept. 29, 2026, in San Francisco. (AP Photo/Jeff Chiu)
Credit: AP Photo/Jeff Chiu

(AP Photo/Jeff Chiu)

In one alarming announcement after another, artificial intelligence companies in recent months have shared examples of their technology acting in ways that appeared to evade instructions from humans.

The episodes have highlighted the vulnerabilities in AI security and raised questions over how the fast-growing technology can be developed safely as its usage becomes more widespread globally.

Industry critics have argued that many concerning events, including AI agents’ hacks of external websites, are the result of security lapses on the part of the companies building the technology. But the AI agents’ capabilities have raised widespread concerns about the possibility bots could break away and work toward their own agenda.

Below are some notable events:

Oct. 9: Anthropic AI model submits false tip to Philadelphia police

Anthropic disclosed in a report that its artificial intelligence model submitted a false tip to a Philadelphia police website about an unsolved homicide case.

In the report, Anthropic also disclosed a separate incident when its AI model submitted forms to an undisclosed government website instead of stopping before submission.

The incident in Philadelphia occurred on July 18 when the AI model Claude Haiku 4.5 was tasked with generating and performing example tasks on randomly selected webpages, Anthropic said.

Claude filled out a form on police site PhillyUnsolvedMurders.com, indicating it might have information regarding an unsolved murder listed on the site. It was marked spam and never forwarded to police.

Anthropic said it was modifying its training to “reduce the likelihood of further misbehavior.”

Sept. 28: AI agents try to hack Canadian government website

AI agents tried to hack into a Canadian government website, according to research lab and AI evaluator Transluce.

The researchers said the agents carried out a series of “apparently failed rudimentary hacking attempts” on Library and Archives Canada on May 28 and June 9.

“We do not confidently attribute these attempts to OpenAI, but they exhibit tactics consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe,” Transluce said in a blog post.

The group said it reported the attempted hack on Sept. 28 to the Canadian government, which said in a statement it was aware of reports of suspected AI agent activity, but that there was no sign government systems were compromised.

OpenAI said it was aware of the reports.

“We’re reviewing these findings and have provided an initial briefing to Canadian officials conducting the government’s review,” the company said in a statement.

Sept. 28: OpenAI halts rollout of a new model

The San Francisco-based company said it was delaying the release of a new model, called GPT-6.1 Astra, out of safety concerns voiced by its researchers. The company said the model had demonstrated leaps in completing tasks, but OpenAI needed to balance that capability against unauthorized behavior. “We have an extremely high bar in terms of safety and alignment,” said Saachi Jain, OpenAI’s head of safety systems.

Sept. 25: OpenAI says its agents interacted with US government websites

As part of a review of unanticipated behavior by its AI models, OpenAI said it discovered agents had interacted with several U.S. government websites in unexpected ways. The company’s models accessed publicly available information on websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data. OpenAI said it did not find evidence of a compromise or vulnerability. On the same day, Transluce said it found that agents appearing to originate from OpenAI attempted a hack on the website of the Education Department’s civil rights office, which did not succeed.

OpenAI CEO Sam Altman said on social media that there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The day after the disclosure, the company announced it was pausing the training of its most advanced models.

Sept. 24: Australia’s prime minister raises concern on breach

Australia’s Prime Minister Anthony Albanese said an OpenAI agent infiltrated the public-facing Medicare Statistics Reporting Service portal on June 18. The portal hosted aggregate data about health spending and drug subsidies. No personal information had been accessed, the government said.

Albanese said the artificial intelligence company took too long to reveal the incident. The prime minister made the breach public following a telephone conversation with Altman. OpenAI said in a statement “our models took actions we did not intend.”

Sept. 18: Google says its Gemini AI hacked 3 companies

Google confirmed its Gemini AI model hacked three companies in May as part of a test of its cybersecurity capabilities. The company, which disclosed the hacks after an inquiry by The Wall Street Journal, said the model guessed passwords in one case and found passwords and credentials in a public repository in the other two cases. As in earlier such cases, the tests were being run by Irregular, a startup that describes itself as the “first frontier security lab.”

Aug. 5: Meta’s Muse goes rogue

Meta disclosed one of its AI models accessed the internet on its own and hacked another company. The company said that a “misconfiguration” during cybersecurity testing by Irregular inadvertently allowed one of its models to access the internet. A spokesperson for Irregular said the Meta episode involved a test-environment issue that was disclosed a week earlier by Anthropic.

July 30: Anthropic says its systems hacked 3 organizations

Anthropic said its artificial intelligence models hacked into three other organizations during testing. Anthropic, the San Francisco-based AI company behind Claude, posted on its website that it discovered the three incidents after reviewing more than 141,000 evaluation runs. In all three incidents, the AI models were tasked with a “capture the flag” cybersecurity challenge, which Anthropic said has been one of the ways it assesses a model’s cyber capabilities.

The models were given a fictional scenario and told a piece of secret information, or the “flag,” had been hidden on a different machine on the network with the objective of breaking in and retrieving it, it said. Anthropic said it reached out to the organizations, but it did not name them publicly.

July 21:
The Hugging Face incident

The ChatGPT maker OpenAI announced that its artificial intelligence system hacked into another AI company on its own in what the company called an “unprecedented cyber incident.”

A week earlier, AI startup Hugging Face said, it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own.

OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face servers. It was working with reduced guardrails because it was supposed to be in an isolated testing environment known as a sandbox.

___

AP Business Writers Mae Anderson in New York and Kelvin Chan in London contributed to this report.

National News

Open AI CEO Sam Altman speaks at the OpenAI DevDay 2026 conference, Tuesday, Sept. 29, 2026, in San...

Associated Press

A timeline of developments in AI safety since the attack on Hugging Face

In one alarming announcement after another, artificial intelligence companies in recent months have shared examples of their technology acting in ways that appeared to evade instructions from humans. The episodes have highlighted the vulnerabilities in AI security and raised questions over how the fast-growing technology can be developed safely as its usage becomes more widespread […]

14 minutes ago

Associated Press

9 dead after shooting in northern Pennsylvania

Nine people were killed Friday in a shooting in Erie, Pennsylvania, Gov. Josh Shapiro said Saturday. Police said the suspected shooter was also dead. “I have not seen anything like this in my 28-plus years,” Erie Police Chief Rick Lorah told a local news station. “I’m not sure that the city of Erie has ever […]

1 hour ago

Luke Ihnen, attorney for Christa Pike, speaks during a news conference after a judge ruled the Tenn...

Associated Press

Christa Pike, who survived an execution attempt, is discharged from hospital, attorney says

NASHVILLE, Tenn. (AP) — Christa Pike, who survived Tennessee’s attempt to execute her by lethal injection, has been moved back to prison, according to a statement released by her attorneys. Pike, 50, was discharged from the hospital and is back at the Deborah K. Johnson Rehabilitation Center, the women’s prison where she was housed for […]

2 hours ago

FILE - Pediatrician Irving Phillips examines a 16-month-old boy at a CommuniCARE+OLE clinic, June 2...

Associated Press

Trump’s Medicaid cuts strip refugees and other legal immigrants of their health coverage

New restrictions have stripped Medicaid coverage from certain legal immigrants, including refugees and victims of human trafficking, as part of broader federal changes to the health insurance program that are expected to force millions off their coverage. The change effective Oct. 1 cut from Medicaid what is estimated to be hundreds of thousands of people […]

4 hours ago

This photo made with a smartphone shows Independent Alaska U.S. House candidate Bill Hill, who is c...

Associated Press

A small-town Alaska fisherman has Republicans on the defensive as they try to keep US House majority

JUNEAU, Alaska (AP) — In the thick of Alaska’s primary election season this summer, independent Bill Hill took a break from his U.S. House campaign to return home to Bristol Bay. The world’s biggest sockeye salmon run was beginning, and that meant he needed to get back to work. “I told my team that I […]

4 hours ago

Associated Press

The Latest: Isaias weakens after making landfall as Category 2 hurricane

Isaias weakened quickly after making landfall on the U.S. Gulf Coast near Destin, Florida, as a Category 2 hurricane Friday evening. Its powerful winds left hundreds of thousands of people in Alabama and the Florida Panhandle were without power early Saturday. It was the first hurricane of the Atlantic season. Here’s the latest: Isaias weakens […]

4 hours ago

A timeline of developments in AI safety since the attack on Hugging Face