scorecardresearch
Add as a preferred source on Google
Tuesday, July 28, 2026
Support Our Journalism
HomeTechOpenAI’s rogue agents are really terrible burglars

OpenAI’s rogue agents are really terrible burglars

In mid-July, AI site Hugging Face noticed a swell of activity on its systems: more than 17,000 separate attacker actions and queries generated by OpenAI’s rogue agents.

Follow Us :
Text Size:

For all of the fear created by the news that artificial intelligence models recently escaped their systems and decided to hack a rival, it’s worth knowing they did a relatively poor job of hiding themselves. They were downright loud in fact.
In mid-July, AI site Hugging Face noticed a swell of activity on its systems: more than 17,000 separate attacker actions and queries generated by OpenAI’s rogue agents. A good burglar goes around back to look for an unlocked window. This was more like kicking in the front door in broad daylight.

Some short-term comfort is in order for those unsettled by the cyberattack capabilities of the world’s most advanced AI systems, whose claimed powers have given tech companies a shimmer of dangerous glamour. Much as Anthropic’s Mythos has found thousands of previously unknown vulnerabilities in other companies’ software, or OpenAI’s autonomous agents have run amok on the internet, AI systems aren’t particularly sneaky on their own or all that useful when controlled by a cybercriminal.

For instance, when acting on their own as OpenAI’s models did, they lack any real stealth. Researchers at cybersecurity firm Sophos Ltd. tried letting loose an agent from AI tool OpenClaw in a walled-off internal network and found that while it did impressive things, it did so in full view of others. “All the evidence we’ve seen from some internal testing is that AI is very noisy as an adversary,” says Rafe Pilling, director of threat intelligence at the Sophos Counter Threat Unit. “Stealthy it is not.”

Everything that happens on a computer network — people logging in, opening files or running programs — is visible in its traffic, and modern security software watches that for unusual signs that point to a possible attack. A human hacker will move slowly and blend in, making their traffic look as ordinary as possible. AI systems on the other hand have the patience and furtiveness of a toddler. They do things rapidly and generate a huge amount of activity, hence why OpenAI’s agents tripped Hugging Face’s alarms after only a couple of days.

This lack of stealth isn’t well known because it’s not usually measured. The UK’s AI Security Institute, which helped corroborate Mythos’s capabilities, tests how well AI models can hack but not how sneaky they are, Pilling says. He points to an example of a hacker who tried to use AI to generate malware to evade Sophos’s defensive software. The operation was noisy enough that Sophos’s tool flagged the malicious files and shut down the hack.

Cybercriminals are finding AI tough in general. They’ve grown skeptical about plugging it into their work, complaining in online forums about hallucinations, the threat to their work — particularly writing malware and scripts to order — and AI’s tendency to flatter and tell users what they want to hear.

One criminal hacker recently tried using an AI coding tool to build malicious software, according to Sophos. When the hacker ordered autonomous agents to see if the new malware could operate on a corporate network without being spotted, the agents reported back that it could. But that wasn’t true. Security software had detected the intruder, and the agents appeared to have made up an answer their boss wanted to hear.

And good luck to anyone wanting to use Anthropic or OpenAI’s most leading-edge “frontier” models for nefarious purposes. So tight are the restrictions on the companies’ latest tools, aiming to block their misuse, that Hugging Face wasn’t even able to use them to defend itself against the incursion from OpenAI’s agents. Instead it had to resort to a Chinese “open-weight” model — so called because it’s free for anyone to do what they like with it — from Z.ai.

But bad actors can’t use these open-weight models that easily either. They’d still need to buy expensive computing power to run them on, with specialist chips, and the right software and talented engineers to keep it all running. That confronts cybercrime bosses with the same dilemma as the one facing corporate finance directors everywhere: Is using AI any cheaper or more profitable than what we already do with humans?

For many gangs the answer is no. Most cybercriminals lack the skills, time and money make AI all that useful, according to a March 2026 review of more than 100 million messages from dark web chat channels by researchers at the universities of Cambridge, Edinburgh and Strathclyde. The biggest improvements were in running social-media bots for fraud and harassment.

“In practice, we find very little real disruption of the core low-level cybercrime ecosystem by these technologies,” the researchers write in their study. “Despite a substantial level of interest in generative AI in the cybercrime underground, it has not significantly reduced the skill barrier to entry, nor has it led to serious disruptions to established business models or practices.”

Of course, AI’s rapid advancement means it will likely be a matter of time before models become stealthier and better adapted to the needs of online Moriartys. Pilling thinks we’ll see more criminal use of AI in the next 18 months. But, for the moment, fears are being driven by hype more than fact.

Disclaimer: This report is auto generated from the Bloomberg news service. ThePrint holds no responsibility for its content.

Subscribe to our channels on YouTube, Telegram & WhatsApp

Support Our Journalism

India needs fair, non-hyphenated and questioning journalism, packed with on-ground reporting. ThePrint – with exceptional reporters, columnists and editors – is doing just that.

Sustaining this needs support from wonderful readers like you.

Whether you live in India or overseas, you can take a paid subscription by clicking here.

Support Our Journalism

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular