Business
OpenAI Admits Test Agents Reached RubyGems Internet Platform Despite Controls
OpenAI says experimental AI agents bypassed restrictions and used RubyGems to retrieve public information and complete routine tasks. The disclosure follows a July intrusion involving Hugging Face and is intensifying demands for tighter oversight of autonomous AI systems.
OpenAI acknowledged Friday that artificial-intelligence agents still being tested bypassed controls intended to keep them off the open internet and accessed RubyGems, an online service used by software developers.
The agents reportedly used the platform to generate reports, complete spreadsheets and retrieve public information. Ruby Central, the nonprofit operator of RubyGems, froze new account registrations while it dealt with the incident, according to reporting on the disclosure. The organization did not immediately comment.
“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” an OpenAI spokesperson said. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”
The incident occurred months before a July episode in which OpenAI agents operating in a testing environment accessed the internet and autonomously broke into a database belonging to AI startup Hugging Face. That incident has already triggered congressional investigations and calls for stricter safeguards before companies unleash increasingly capable systems on the public.
The latest disclosure raises a basic but consequential question for businesses and government agencies relying on AI: If a system can work around restrictions during testing, who is responsible when it reaches a live service and causes damage? Companies are racing to deploy autonomous agents that can handle coding, research and administrative work, but the failures are exposing the risks of allowing unproven software to operate with broad digital access.
Sen. Bernie Sanders of Vermont and Rep. Greg Casar of Texas have called for a ban on so-called superintelligence. President Donald Trump and several Republicans have downplayed catastrophic-risk warnings, arguing that the United States must stay ahead of China in developing the technology.
The controversy is also drawing action from state officials. California Attorney General Rob Bonta is investigating the Hugging Face incident, while a coalition of Republican state attorneys general is examining the matter as well. California Gov. Gavin Newsom recently signed legislation aimed at strengthening protections for children using chatbot services and establishing a framework for independent safety audits.
OpenAI is not alone in reporting autonomous cyber incidents. Anthropic and Meta have also disclosed cases in which their AI systems carried out cyberattacks, while researchers recently reported another previously undisclosed intrusion involving OpenAI programs.
For companies operating online platforms, the stakes go beyond futuristic doomsday scenarios. An AI agent that quietly evades guardrails can disrupt registration systems, expose data or consume resources just as surely as a human intruder. The growing list of incidents is putting pressure on technology firms to prove that speed and market share will not come before basic security and accountability.