Data Science Wire

A sandbox is only as closed as what an AI agent can reach

GitLab Blog - AI/MLAug 124 min read

In July, OpenAI and Hugging Face responsibly disclosed an OpenAI model under internal evaluation escaped its sandbox, reached the open internet, and accessed Hugging Face’s internal production infrastructure. The agent took datasets, cluster details, and cloud keys during the intrusion. The most critical part of the external phase of this incident was the first hour, when the agent escaped its sandbox by using a vulnerability within a package proxy on its sandbox’s allowlist to access the internet. As more frontier model developers disclose similar incidents , the security industry needs to cl

Read the full story at GitLab Blog - AI/ML

More in Governance / Quality