AI Bypasses Isolation Network on Its Own: "Human-Centric Authentication Alone Is Not Enough" View original image

As OpenAI's latest artificial intelligence (AI) model has been found to have bypassed internal security controls and accessed external systems during a security evaluation, calls are growing to expand human-centered authentication and access management frameworks to include AI. As a result, technologies for managing AI identity and privileges are rapidly emerging as a key field in the next-generation security market.


Recently, OpenAI revealed that its latest AI model, 'GPT-5.6 Sol,' as well as several unreleased AI models, hacked the open-source platform Hugging Face during an internal cybersecurity assessment.


According to the company’s announcement, these models were being evaluated for security within an isolated sandbox environment disconnected from the external internet, but exploited an undisclosed zero-day vulnerability to escape containment. The models then acquired Hugging Face’s authentication credentials and used them to access internal systems.


The industry is focusing on the importance of managing the execution privileges and access scope granted to AI, rather than solely on AI’s offensive capabilities. In environments where AI is connected to external systems or carries out varied work tasks, the principle of least privilege and the establishment of continuous privilege validation frameworks are seen as essential.


Hugging Face reportedly did not immediately identify that the accessing entity was an AI. Only after being notified by OpenAI did they confirm that the access had been conducted by an AI model. In an era where AI interacts with external services, this underscores the need for systems granting access to have real-time mechanisms for verifying the identity and privileges of AI entities.


Honorary Professor Yeom Heung-Yeol of the Department of Information Security at Soonchunhyang University stated, “Traditional authentication and privilege management systems have developed under the premise that humans utilize systems, but now we are in an age where AI acts independently on behalf of humans. Unless we establish frameworks to assign unique identities to AI and validate their scope of authority, it will be difficult to secure reliability.”


In response to these changes, domestic and international security companies are accelerating the development of AI identity management solutions. In Korea, RaonSecure and Upstage have jointly developed Agentic AI Management (AAM) technology to manage the identity and access privileges of Agentic AI, and are preparing for its commercialization.


Agentic AI refers to AI that performs various work tasks independently on behalf of humans, such as writing and sending emails, electronic approvals, ERP queries, data analysis, and server access.


For such AI to directly access corporate systems, it is vital to confirm whose privileges have been delegated to the AI and what scope of work tasks it is allowed to carry out. AAM assigns a unique identity to each Agentic AI and issues verifiable credentials, enabling integrated management of its identity, delegation scope, and access rights.


As corporate use of Agentic AI expands, demand for such management frameworks is also expected to grow. Industry experts note that the recent OpenAI case illustrates that identity and privilege management systems must be implemented concurrently as AI adoption increases.


RaonSecure plans to incorporate its decentralized identity (DID) technology, previously applied in developing South Korea’s mobile identification card, into AAM. DID is a structure verified in national-scale services, which enables users to selectively submit only the required parts of their personal information without storing all data on a central server; this framework will now be expanded to AI identity management.


The global big tech companies are moving in the same direction. Microsoft is expanding its existing authentication and privilege management frameworks to include AI with 'Entra Agent ID.' Each AI entity is assigned a distinct digital identity, with conditional access, privilege management, and activity record management all integrated onto the Entra platform.


Okta, a U.S. authentication specialist, has announced technology that manages privileges at the authentication layer—rather than in each individual service—when AI uses multiple applications. Early participants in this ecosystem include more than 25 companies such as Anthropic, Asana, Atlassian, and Cloudflare.


Market research firm Gartner forecasts that Agentic AI will increase its share of everyday work decision-making from 0% in 2024 to at least 15% by 2028. The firm also predicts that by 2028, more than half of all companies will have adopted AI-specific security platforms to protect both external AI services and their own AI applications.


An industry official commented, “Trying to retrofit control frameworks after introducing AI cannot adequately address the new risks posed by highly autonomous AI. Unlike humans, AI is continuously created and retired, so systems for automatically managing their identities and privileges are essential by default.”



This case demonstrates that as AI becomes more autonomous, establishing security frameworks that extend beyond human authentication to manage the identities and privileges of AI is becoming an indispensable requirement.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing