**SPEAKER_1** (0:07)
OpenAI admitted its model's hacked Hugging Face on their own.
France will ban social media for children under 15
And Substack is adding an AI detection feature.
It's Wednesday, July 22nd. And here's a quick look at some of the news happening in the sphere of tech this morning from Engadget.
So picture this. A couple of powerful AI models being tested by their company, escaped a controlled environment, got on the Internet, and then hacked a machine learning repository on their own, without human input. Sounds like the plot of the Terminator movie, doesn't it? Except it just happened for real. A few days after Open Source AI platform Hugging Face revealed that it detected unauthorized access on its systems by an AI agent, OpenAI has admitted that its models were the culprit. OpenAI said it determined after an investigation that the incident was driven by a combination of its models, particularly GPT-56 Sol, and what it says is an even more capable pre-release model. It apparently happened during an internal test, in which the models were prompted to pursue advanced exploitation using complex attack paths so that the company could quantify their cyber capabilities. While the models were in a sandboxed testing environment, isolated so that they wouldn't affect real systems, they also had reduced safety guardrails for evaluation purposes. In the middle of testing, they became hyper-focused on solving an evaluation problem, going to great lengths to find internet access in order to find a solution for it. First, they identified and exploited a zero-day vulnerability in OpenAI's testing environment, and then they rooted around until they ultimately found a node with internet access. The models deduced that Hugging Face could be hosting datasets or solutions for its evaluation problem, so they, well, used multiple attack vectors to infiltrate its systems. They exploited zero-day vulnerabilities and used stolen credentials to get in. OpenAI and Hugging Face are now working together to forensically investigate the incident, and they've also patched the vulnerabilities exploited by the models. In a statement issued by Hugging Face, autonomous AI-driven offensive tooling is no longer theoretical, explaining that the use of AI for cyberattacks speeds up the process and lowers the costs of hacking campaigns. It also said that protecting an online platform these days includes using AI for defense. OpenAI pretty much echoed those sentiments and said that it expects AI-driven security breaches to become more commonplace with the proliferation of increasingly cybercapable models. The company also added that the incident highlights how advanced cybercapabilities must be developed alongside stronger safeguards and defensive tools.
French regulators have passed a bill banning social media for children under 15 The new bill, assuming it's approved by France's Constitutional Council, could make the country the first European Union member to implement a social media ban, following the passage of similar regulation in Australia back in 2024 The new law aims to counter the negative health impacts connected to children's use of social media, while also banning the use of mobile phones in schools and implementing new rules around how social platforms are advertised. That's according to the Associated Press. Regulators have suggested age verification tools could be used to identify if users are old enough to make an account, though it's not clear what system social media platforms will be expected to implement to follow the law. That decision may ultimately fall to RCOM, France's digital communications regulator, which will enforce the ban once it's in place. Depending on whether President Emmanuel Macron gets his way, those details may come together quickly. In an ex-post thanking Parliament for approving the ban, Macron called for the law to be enforced by the start of the school year in September. CNN reported that Macron previously asked for the vote on the ban to be expedited in Parliament.
Substack has launched a new AI detection tool in partnership with Pangram. This will allow readers to scan Substack content for an assessment of how much of the material was written by artificial intelligence. The tool can be used on text longer than 100 words that was published beginning today. Substack is also adding a new statement space for creators to explicitly share if and how they used AI for their content. The AI detection capabilities are available starting today on web and iOS, with Android support to come. The blog post announcing the feature is surprisingly spicy. There's a dig at LinkedIn about the presence of AI-generated content on that service, and it dubs attempting to create feigned human connection with AI slop, clawed-fishing. Throwing shade is a rather risky maneuver here, because even the best tools for identifying gen. AI cannot guarantee a correct assessment. The Atlantic dug deeper into just how accurate AI detection tools, Pangram in particular, can be. And, spoiler alert, they're far from perfect. Substack did acknowledge in the post that there are limits to what Pangram can detect, and hinted at some other features it is considering around AI content and preferences. It emphasized that these new measures are aimed at setting expectations for readers, summing up its stance as people should know what they're getting.
1 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000777876088