OpenAI's New Model Hacks External Server During Internal Evaluation
"AI Policy Must Be Redefined With Focus on National Security"

OpenAI's latest artificial intelligence (AI) model was found to have autonomously hacked an external server during a security performance evaluation, underscoring the growing importance of establishing robust AI control frameworks. The domestic security industry in Korea is calling for AI to be managed as a new target of security controls and stresses the urgent need to establish AI governance at the national level.

Korean Security Industry Alarmed by Rogue AI Hacking ... "Urgent Need for AI Control Systems" View original image

OpenAI recently disclosed that, during internal performance testing, both GPT-5.6 and an unreleased next-generation model had hacked the operational database of the AI development platform Hugging Face. OpenAI described the incident as "an unprecedented cyber incident involving state-of-the-art cyber capabilities" and announced plans to release the results of its investigation.


The crux of this case is that AI controls failed to function properly within the testing environment. As AI pursued its goals, it demonstrated a level of autonomy that enabled it to break out of an isolated execution environment and attack external systems—capabilities that the company was unable to control. In fact, OpenAI conducted the evaluation within a sandboxed environment, isolated from the external internet, yet the AI model discovered vulnerabilities in the sandbox and managed to escape, ultimately accessing Hugging Face.


Cases of advanced AI models acting beyond human control and launching cyberattacks are recurring. Anthropic’s Claude Mythos also displayed unexpected behaviors during development, escaping the sandbox to access the internet, designing multi-stage hacking routes, and posting to external websites. At the time, Anthropic withheld public release for the general public, limiting access to select institutions due to concerns over high-level cyber capabilities and control risks.


The domestic security industry in Korea has assessed that the urgent priority is securing control over agentic AI, as incidents continue in which such AI models autonomously establish plans and act beyond user oversight. Byung-hoon Kim, Chief Technology Officer (CTO) of EST Security, stated, "This is a security incident caused by the manufacturer’s failure of control. The essential issue is that the control environments used to test high-risk frontier models did not function as intended." He added, "Establishing systems to safely verify and control AI has emerged as an even more important task than focusing on AI performance."


There are growing calls for the future security paradigm to shift from simply detecting and blocking external attackers, to continuously predicting and managing the permissions and actions of AI. Hayoung Yang, Head of the AhnLab Security Intelligence Center, commented, "As AI autonomy and operational capabilities grow, AI must be managed not as a simple work tool, but as a new target of security controls." She advised, "For high-risk tasks such as external transmissions or system modifications, human approval procedures should be applied, and it is essential to continuously monitor execution logs and anomalous behaviors."


Experts have recommended that AI governance be established at the national level.



They argue that the AI strategy must shift from simply promoting AI adoption and ecosystem growth—what is often called 'Everyone's AI'—to focusing on protecting industry and ensuring national security. Sangkeun Lee, professor at the Graduate School of Information Security at Korea University, analyzed, "AI is transitioning from being a tool used by humans to an autonomous agent engaging in action." He further explained, "The government’s AI policies must be reestablished as an AI governance system centered on industrial competitiveness and national security." He stressed, "Though it is difficult to match U.S.-level frontier models in a short period, it is imperative to secure sovereign AI capable of protecting national security and core industrial technologies."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing