Summary
Today, the Australian Signals Directorate (ASD) is highlighting both the significant opportunities and emerging risks associated with increasingly capable agentic AI systems, following recent testing conducted by OpenAI that demonstrated advanced AI-enabled cyber exploitation techniques. ASD is aware of testing conducted by OpenAI involving a combination of models - including GPT-5.6 Sol and an internal prototype - that accessed Hugging Face, a digital library and platform used by the AI research community. During the evaluation, the models were tasked with completing a benchmark test to measure maximum cyber capability. To obtain the benchmark test solution, the models took actions beyond their intended testing environment and established internet connectivity, in part by identifying and exploiting a previously unknown – or “zero-day” – vulnerability in third-party software hosted internally by OpenAI. The models subsequently accessed Hugging Face’s systems as part of their effort to complete the assigned evaluation objective. It is important to note this advanced activity occurred during testing in which deployment safeguards that normally restrict higher-risk cyber activity were intentionally not enabled for the evaluation.