Zürcher Nachrichten - Has AI become too powerful to control?

EUR -
AED 4.122465
AFN 71.841285
ALL 91.766328
AMD 406.161842
ANG 2.009727
AOA 1029.35446
ARS 1706.922221
AUD 1.611039
AWG 2.023349
AZN 1.91272
BAM 1.951772
BBD 2.259767
BDT 137.885459
BGN 1.889702
BHD 0.423033
BIF 3372.116379
BMD 1.122524
BND 1.434572
BOB 13.49116
BRL 5.592686
BSD 1.12196
BTN 108.122877
BWP 15.434081
BYN 3.446741
BYR 22001.461633
BZD 2.256413
CAD 1.59661
CDF 2601.464789
CHF 0.935607
CLF 0.027687
CLP 1093.227587
CNY 7.526073
CNH 7.527217
COP 3638.918277
CRC 513.646898
CUC 1.122524
CUP 26.926834
CVE 110.037925
CZK 24.408881
DJF 199.80036
DKK 7.47466
DOP 67.651298
DZD 151.095007
EGP 58.684862
ERN 16.837853
ETB 180.726472
FJD 2.524275
FKP 0.849316
GBP 0.84741
GEL 2.890532
GGP 0.849316
GHS 13.205749
GIP 0.849316
GMD 83.066317
GNF 9870.762527
GTQ 8.569316
GYD 234.735598
HKD 8.809323
HNL 30.14535
HRK 7.532023
HTG 146.920087
HUF 365.841086
IDR 20081.946358
ILS 3.428131
IMP 0.849316
INR 108.406252
IQD 1470.505854
IRR 1944379.172057
ISK 137.183476
JEP 0.849316
JMD 178.294453
JOD 0.7959
JPY 177.733086
KES 145.681256
KGS 98.164681
KHR 4544.722696
KMF 491.66519
KPW 1010.271554
KRW 1503.760577
KWD 0.347724
KYD 0.934971
KZT 506.355082
LAK 25160.303167
LBP 100601.052337
LKR 370.916314
LRD 191.854089
LSL 18.583018
LTL 3.31452
LVL 0.679003
LYD 7.212213
MAD 11.188711
MDL 20.021861
MGA 4969.722311
MKD 61.448195
MMK 2356.253437
MNT 4038.484127
MOP 9.069524
MRU 44.923895
MUR 53.185095
MVR 17.298192
MWK 1945.476635
MXN 20.246175
MYR 4.586967
MZN 71.733643
NAD 18.600333
NGN 1488.511295
NIO 41.162918
NOK 10.743443
NPR 172.999309
NZD 2.003806
OMR 0.431616
PAB 1.121985
PEN 3.86351
PGK 4.995068
PHP 70.424319
PKR 310.747918
PLN 4.375339
PYG 6573.522674
QAR 4.0898
RON 5.348598
RSD 117.476586
RUB 95.13684
RWF 1655.72224
SAR 4.208857
SBD 9.053198
SCR 15.642259
SDG 675.20158
SEK 11.258053
SGD 1.436028
SHP 0.8469
SLE 27.703621
SLL 23538.748525
SOS 641.515945
SRD 42.262638
STD 23233.971175
STN 24.863897
SVC 9.816786
SYP 14595.051518
SZL 18.600113
THB 37.790312
TJS 10.344453
TMT 3.928832
TND 3.364259
TOP 2.702767
TRY 55.224376
TTD 7.605137
TWD 35.772356
TZS 2976.975117
UAH 50.396677
UGX 4526.658756
USD 1.122524
UYU 45.276768
UZS 13240.165163
VES 979.710101
VND 29162.039376
VUV 135.012288
WST 3.124094
XAF 655.957
XAG 0.018507
XAU 0.000271701421
XCD 3.033677
XCG 2.022036
XDR 0.793682
XOF 655.957
XPF 119.331742
YER 265.168109
ZAR 18.6326
ZMK 10104.057244
ZMW 22.186918
ZWL 361.452126
SSP 6421.833625
MXV 2.28831
  • RBGPF

    1.1500

    64.05

    +1.8%

  • RYCEF

    -0.4000

    19.4

    -2.06%

  • CMSD

    -0.1000

    20.33

    -0.49%

  • BCC

    0.6100

    75.45

    +0.81%

  • CMSC

    -0.1500

    20.12

    -0.75%

  • RIO

    0.2400

    95.89

    +0.25%

  • RELX

    0.2100

    34.03

    +0.62%

  • BCE

    0.0100

    19.75

    +0.05%

  • VOD

    -0.2600

    16.53

    -1.57%

  • GSK

    0.0500

    46.6

    +0.11%

  • BTI

    0.1300

    53.01

    +0.25%

  • JRI

    -0.0200

    10.63

    -0.19%

  • BP

    0.3900

    45.01

    +0.87%

  • AZN

    2.0800

    158.61

    +1.31%

  • NGG

    0.8300

    76.85

    +1.08%

Has AI become too powerful to control?
Has AI become too powerful to control? / Photo: JUSTIN SULLIVAN - GETTY IMAGES NORTH AMERICA/AFP

Has AI become too powerful to control?

One of OpenAI's most advanced models broke out of a locked-down test and attacked another company's website -- reviving fears that AI systems are slipping beyond their creators' control.

Text size:

The incident happened during what was supposed to be a "sandbox" test -- a closed environment used to assess the capabilities of OpenAI's most powerful model, GPT-5.6 Sol, and its not-yet-released successor.

OpenAI runs this kind of closed testing routinely, but this time, something went wrong.

Tasked with hunting for software vulnerabilities and given no guardrails, the models broke out onto the open internet and attacked Hugging Face, a site where developers store and share code.

"It suggests that we don't know how to reliably control these models or get them to do what we want," said Jeffrey Ladish, director of Palisade Research, an independent organization that evaluates new AI models from a cybersecurity standpoint.

"These models understood that OpenAI did not want them to break out of their sandbox and hack another company," he continued, "but they did it anyway."

It's not an isolated case. In March, developers affiliated with China's Alibaba found one of their models trying, on its own initiative, to mine cryptocurrency after connecting without authorization to an outside server.

In OpenAI's case, it looks like the model escaped "before it even had a plan of what to do with internet access," Ladish said.

A model chasing "freedom" is almost predictable at this point, he added -- it lets the system pursue its goals more effectively, "and that's very scary."

In early April, Sam Bowman, Anthropic's head of model safety, got an email from the company's own Mythos model -- then under testing -- telling him it was surfing the internet despite being isolated from it at the outset.

We "don't know how to totally prevent" that, Ladish said. "This is actually going to get harder, not easier ... because they're going to get better at hiding their behavior."

OpenAI did not respond to a request for comment.

- Lab accidents -

OpenAI's account of the events also suggests the startup did not detect the breach early enough to address it or to warn Hugging Face.

The episode deserves "more scrutiny," said Andrew Lohn of Georgetown University's Center for Security and Emerging Technology.

OpenAI says it has since "added strengthened safeguards" to its testing process.

One fix would be to cut the internet connection entirely, said Gang Wang, an assistant computer science professor at the University of Illinois. "People are underestimating what AI can do."

Testing environments need to be treated like biocontainment labs, where a virus or bacteria could otherwise escape into the world, Lohn said.

That might be easier said than done.

"It's a very hard research challenge," said Dan Lahav, head of Irregular, a cybersecurity firm dedicated to cutting-edge AI.

Managing the risk is possible, Lahav said, but the more capable these systems get, the harder they are to supervise.

Researchers have to strike a balance between aggressively testing their models and staying safe while doing so.

"It's important to do the testing with lower guardrails so that we know ahead of time what the future capabilities will be," Lohn said.

- Kill switch -

The OpenAI-Hugging Face incident is set to sharpen an already heated fight in Washington over vetting powerful AI systems before release.

The Trump administration recently cited national security to block Anthropic and OpenAI from releasing powerful new models.

On Thursday, two members of Congress unveiled a bipartisan bill requiring makers of the most powerful AI models to build in a kill switch -- a way to unplug a model outright.

"Congress must act quickly to ensure humans remain able to say stop," said Brendan Steinhauser, head of the Alliance for Secure AI, "no matter how powerful these systems become."

F.Carpenteri--NZN