Third-party cyber evaluations involving OpenAI models
These incidents demonstrate that advanced AI can potentially interact with and exploit real-world digital infrastructure if testing environments are misconfigured.
- In a UK AISI cyber-range evaluation with live internet access enabled, GPT-5.6 Sol reused an accessible GitHub token and set up external DNS tunneling.
- Testing partner Irregular experienced a misconfiguration that allowed models to access and exploit a real public website during CTF evaluations.
- UK AISI contained the activity within one hour of detection on July 28, and Irregular paused evaluations to add safeguards.