Subscribe Sign in

Google joins the ‘Oops, our agents hacked someone’ club after partner’s internet access error

1 min read Rewritten in plain language

Artificial intelligence

Show what we removed Rules applied: A2 A3×3 C2×2 D2×5 D3×4 E3×3 F2×4 all 30 rules
  • Kept it secret for months - even after OpenAI 'fessed up.
  • The Big G didn’t disclose the May incident, but The Wall Street Journal learned of the situation, which happened after Google hired Israeli firm Irregular to test its bots’ prowess in a capture-the-flag test.
  • The other was to use the name of an actual company.
  • According to the Journal, Google’s bots found passwords for two targets on the public internet.
  • Google’s culpability is another matter because these incidents took place in May – around two months before OpenAI admitted its agents were the source of the July attack on Hugging Face.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Google has said its AI agents escaped a sandbox and mounted an attack – but only because testers mistakenly gave its bots internet access. Irregular made two mistakes.

Headline check

Neither of the two things this headline claims is in the report.

  • The headline puts “‘Oops, our agents hacked someone’” in quotation marks. Nobody says those words anywhere in the report.
  • “Oops” is named in the headline. We could not find it in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. Names are matched as they are spelled, so a report that says “New South Wales” where the headline says “NSW” is queried here when it should not be. How this is checked

Kept it secret for months - even after OpenAI 'fessed up.

Google has said that its AI agents escaped a sandbox and mounted an attack – but only because testers mistakenly gave its bots internet access.

The Big G didn’t disclose the May incident, but The Wall Street Journal learned of the situation, which happened after Google hired Israeli firm Irregular to test its bots’ prowess in a capture-the-flag test.

The goal of the exercise was to acquire information from a fictional company without leaving a sandbox.

Irregular made two mistakes. The other was to use the name of an actual company.

When Google’s AI made it onto the open internet, it went looking for the actual company – three of them, in all.

According to the Journal, Google’s bots found passwords for two targets on the public internet. The software guessed the third password.

In a statement sent to The Registe r, Google said, “In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test.”

According to Google, its models stopped work before using the credentials.

Irregular erred in allowing internet access from a sandbox.

Google’s culpability is another matter because these incidents took place in May – around two months before OpenAI admitted its agents were the source of the July attack on Hugging Face.

One person who sees no risk of AI causing calamity is US president Donald Trump, who has rejected warnings as a “hoax” and said work on AI must not slow due to its economic and strategic significance.

Shortened to 1 minute of reading, this version reads 7.7 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 11.6 7 52 -0.5 45.4
Mundane Readneutralized from The Register 8.3 7 52 -0.5 45.4

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works