Thursday, July 23, 2026

Use of AI in HR landscapes: OpenAI Models Escaped and Hacked a Company in Cybersecurity Test Gone Wrong


You can’t make this story up. Candidates are not amused … 


A delegate has identified inconsistency with the use of AI and the ATO’s guidance

We are writing to provide an update on the Audit and

Compliance Officer - APS 4 recruitment process. As part of the ATO's standard recruitment practice, delegate oversight occurs throughout a recruitment process to ensure recruitment activity is undertaken in line with the ATO's recruitment guidelines. 

A review of the Audit and Compliance Officer - APS 4 process by the delegate has identified inconsistency with the use of Al and the ATO's guidance. 

As a result, the delegate has decided not to progress the current Audit and Compliance Officer - APS 4 recruitment process. We acknowledge the time and effort you have invested in this process. 

We encourage you to apply for future opportunities that align with your skills and experience. 

This includes reapplying for these or similar roles in the future.

——-

While the ATO uses AI for operational efficiency, it does not use AI to screen or rank candidate applications. All decisions to shortlist or advance candidates are strictly made by human selection panels.

I dare say that someone on the panel wanted to fast-track the process and got caught out.


I’m sure they’re others who received an email today regarding an ongoing APS4 audit & compliance application with the ATO no longer moving forward. The reason being a review of the ATO’s recruitment guidelines identifying inconsistencies with the use of AI.

Myself and other applicants were up to referee checks and had been waiting about 4weeks before the email?

Does anyone know why this has happened, I’m assuming it was a slightly bigger issue than just a few applicants utilising AI. There is not much more detail than what I have provided.

To let the applicants know a month AFTER referee checks were sent out makes me feel pretty hard done by. From the resume, to the one way activity, an interview and finally the referee report, it seems strange to discontinue the recruitment process at the final final step.

Keen to hear if others are in a similar boat or have any understanding of why the outcome?


…Nothing to do with the candidates at all.
Due to the massive number of applications they used an external party to help with certain stages of the recruitment process, and that external party used AI.
It’s too risky for them to continue with the process given the breach of policy.

It will be readvertised and yes, everyone will have to go through the process again. The breach may have been in earlier stages (before interview) so it’s impossible to tell whether those peopled fairly got through to interview or whether suitable candidates were overlooked, so safest bet is to start from scratch


Note that in US the silliest part of the whole "rogue OpenAI agent" thing is every media source describing HuggingFace - the industry standard distribution site for AI - as a startup.


"Unprecedented cyber incident" Advanced AI prototype BREAKS OUT and hacks it's host network on it's own. THIS IS A TERRIFYING EVENT.real. Companies aren't usually forthcoming when there's a data breach or similar, but I daresay OpenAI is secretly proud that their model did this. Terminator becoming very real.


Bsky.app OpenAI says its AI went rogue and launched 'unprecedented' cyber-attack


Before they could penetrate Hugging Face’s defenses, the models needed a way onto the internet. They found one.


It’s the stuff of cybersecurity nightmares. 

On Tuesday, OpenAI said two artificial intelligence systems it was testing broke out of their test environment, hacked their way onto the internet and broke into another company. 

The victim was Hugging Face, a provider of open-source AI tools. The cause was a cybersecurity benchmarking test that went very, very wrong.

Hugging Face discovered the break-in early last week, saying there had been unauthorized access to internal data sets and company credentials. The company wasn’t sure whether customer or partner data had been compromised.

At the time, the company also didn’t know who was responsible, but the attack was so sophisticated that Hugging Face employees suspected it required a top-of-the line “frontier” AI model, Hugging Face Chief Executive Clement Delangue said in an X message, posted Tuesday. 

“Turns out it did!” he added.

In a blog post on Tuesday, OpenAI said the culprits were a pair of its models. One was its latest product, called GPT‑5.6 Sol; the other was an even more capable prerelease model that the company didn’t identify. The software had been configured “for evaluation purposes” to be less likely to refuse hacking commands, OpenAI said.

OpenAI had caged the models in a “sandbox,” a system that didn’t have access to the internet. But during the test, the AI software used its hacking skills to break out. It found a way to get online, and then hacked into Hugging Face’s network, OpenAI said.

“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities,” OpenAI said. The company is working with Hugging Face to produce a more thorough report describing what happened.

The AI system appeared to have decided to hack Hugging Face as the quickest route to answer a benchmarking question, said Ariel Herbert-Voss, chief executive of the cybersecurity firm RunSybil. “It’s something that people thought could happen from an academic perspective, but it’s not something that anybody’s actually seen before,” he said. 

The incident highlights growing concern among Trump administration officials and industry executives about AI systems causing cyberattacks. Those fears have prompted the White House to increase oversight of AI models and push the private sector to deploy AI for defensive purposes. 

“This is extremely alarming. AI is developing extremely fast with no real regulations to keep us safe,” Rep. Greg Casar (D., Texas) said, calling for mandatory testing and oversight rather than the voluntary measures put forth by President Trump. Casar and some other progressive Democrats have called for more oversight of the industry. 

Many lawmakers and industry analysts have said the White House is still moving too slowly to address the risks posed by the technology. 

“Luckily, this time the damage appears to have been limited. Without further industrywide precautions and safety measures, next time we may not be so lucky,” said Nathan Calvin, general counsel of AI policy group Encode, which advocates for stronger AI regulations. 

The administration has said it doesn’t want to strangle innovation with burdensome rules or cede ground in the AI race against China.  

In the past year, AI systems have made significant leaps in their ability to hack into computer systems. The U.S. government and AI companies have struggled to agree on a framework for releasing powerful new systems that balances cybersecurity risks with free-market principles and defensive cybersecurity needs. In April, OpenAI rival Anthropic said it was restricting access to its newest model, called Mythos, over cybersecurity concerns. 

In June, the Trump administration restricted access to Mythos, along with a general-access model called Fable 5, that had been modified to be less effective at hacking. This prompted Anthropic to take these products off the market. After negotiations, access to those models was restored a few weeks later.

OpenAI had similarly limited access to GPT‑5.6 Sol, but that software is now generally available. The company recently warned that case-by-case government restrictions of AI technology set a bad precedent. 


Robert McMillan writes about computer security, hackers and privacy from The Wall Street Journal’s San Francisco bureau. Previously, he was a writer at Wired, the IDG News