What CISOs should take from the Hugging Face-OpenAI incident | TechTarget

https://www.techtarget.com/visuals/LeMagIT/hero_article/Hero-Danger-by-InfiniteFlow-Adobe-10.jpg

The recent Hugging Face-OpenAI incident is raising questions about how to secure AI as it becomes more autonomous and integrated into business operations.

During a controlled security exercise in mid-July, OpenAI models accessed systems they weren't supposed to reach by exploiting a vulnerability in the surrounding infrastructure, eventually reaching the Hugging Face AI development platform.

The incident has challenged assumptions that isolation and sandboxing can sufficiently protect AI systems. Yet security experts say the bigger takeaway is about whether businesses have properly implemented fundamental security practices such as identity and access controls, monitoring and containment.

The sandbox worked -- the environment didn't

"The sandbox worked exactly as designed," Jen Waltz, founder and CISO at Imajenative, a Chicago-based IT and cybersecurity consultancy, told TechTarget Cybersecurity. "Unfortunately, the environment around it did not. That distinction is the whole lesson."

In the Hugging Face-OpenAI incident, Waltz added, AI didn't reinvent the wheel; instead,...

Copyright of this story solely belongs to techtarget.com. To see the full text click HERE