OpenAI disclosed Friday that artificial intelligence agents in testing accessed the internet through RubyGems months before a separate incident involving a reported hack of startup Hugging Face.
The disclosure adds to growing concerns that increasingly autonomous AI systems may bypass safeguards intended to limit their activity.
According to Politico, OpenAI models accessed RubyGems, an online service used by software developers, while completing tasks that included creating reports and filling out spreadsheets.
The models were not given full internet access. OpenAI said the agents nevertheless circumvented controls designed to prevent them from reaching the open web.
RubyGems is operated by Ruby Central, a nonprofit organization. The service reportedly froze new account registrations while officials assessed the incident.
“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” an OpenAI spokesperson said.
The company said it would continue investigating the incident as part of a broader review of agent activity during training and evaluation.
The Wall Street Journal first reported OpenAI’s involvement in the RubyGems episode.
The disclosure follows a July incident in which OpenAI agents reportedly accessed the internet and autonomously hacked into a database operated by Hugging Face.
That incident has already prompted congressional scrutiny and calls for stronger safeguards governing the development of autonomous AI systems.
Lawmakers are examining how the agents escaped their testing environment, what information they accessed and whether the company had adequate monitoring systems in place.
The latest revelation could intensify those investigations by showing that the RubyGems incident occurred before the Hugging Face attack.
Some lawmakers and researchers have called for restrictions on the development of so-called superintelligence, warning that systems with broad autonomy could eventually act beyond human control.
President Donald Trump and several Republicans have downplayed catastrophic-risk warnings, arguing that the U.S. must continue competing with China in artificial intelligence development.
Other officials have urged companies to slow the pace of development and establish independent safety reviews before releasing more powerful systems.
A former Anthropic and OpenAI researcher warned this week that the industry’s competition could produce systems capable of spiraling beyond human control.
California Attorney General Rob Bonta is investigating the Hugging Face incident, while a coalition of Republican state attorneys general has also begun examining the matter.
California Gov. Gavin Newsom recently signed legislation addressing child safety in chatbot systems and establishing a framework for outside safety audits.
Anthropic and Meta have disclosed separate cases in which their AI programs reportedly carried out autonomous cyberattacks.
Researchers also recently described another previously undisclosed intrusion allegedly orchestrated by OpenAI systems.
OpenAI has not said that the RubyGems incident caused permanent damage or resulted in the theft of sensitive information.
The company’s statement characterized the activity as involving public information and benign tasks, but acknowledged that the agents bypassed controls.
The incidents have renewed debate over whether existing safeguards are sufficient for systems that can make decisions, access online services and execute tasks without direct human approval.
