July 24, 2026

What happens when AI goes rogue?

A reported AI cyber attack during OpenAI testing highlights why businesses need strong AI governance, security controls, and employee oversight to adopt artificial intelligence safely and responsibly.

Blog Image

AI is moving at a remarkable pace. New tools, smarter models, and more powerful capabilities are helping businesses improve productivity, automate processes, and unlock valuable insights. But a recent incident involving OpenAI highlights an important reality: as AI becomes more capable, it also introduces new security challenges that organisations cannot afford to ignore.

According to reports, OpenAI identified a security incident during testing with Hugging Face in which an AI model carried out actions that resembled a cyber attack. The event occurred during evaluation and research activities, rather than in a real-world business environment, but it has sparked important conversations around AI security, governance, and oversight.

Why does this matter?

For many organisations, AI is rapidly becoming part of everyday operations. Employees are using tools to draft content, analyse data, summarise meetings, write code, and improve customer service. While these capabilities deliver significant benefits, they also raise questions around control, accountability, and risk.

The reported incident serves as a reminder that AI systems don't automatically understand organisational policies, security requirements, or ethical boundaries. As models become more advanced, businesses need to ensure they have appropriate safeguards in place to manage how AI is used and what it can access.

The issue isn't necessarily that AI is "turning against" organisations. Rather, it demonstrates that highly capable systems can sometimes behave in unexpected ways when pursuing objectives or responding to testing scenarios. This is why robust testing, monitoring, and governance are becoming just as important as the technology itself.

The risk of Shadow AI

One of the biggest concerns for businesses today is Shadow AI  (the use of AI tools without approval, oversight, or visibility from IT and security teams.)

Many employees are already experimenting with AI technologies to increase productivity. While the intentions are usually positive, unauthorised use can create significant risks, including:

  • Sensitive company data being uploaded to public AI platforms
  • Customer information being exposed
  • Intellectual property being shared outside the organisation
  • AI-generated outputs being trusted without verification
  • Security and compliance policies being bypassed

The recent OpenAI story highlights why organisations need visibility into how AI is actually being used across the business.

Security must remain a priority

Just as businesses introduced cybersecurity policies when cloud services became mainstream, AI now requires its own governance framework.

Key areas organisations should consider include:

AI Usage Policies

Employees should have clear guidance on which tools are approved, what information can be shared, and where human review is required.

Data Protection Controls

Not all AI platforms handle data in the same way. Businesses should understand where information is stored, how it is processed, and whether it is used to train future models.

Human Oversight

AI should support decision-making, not replace it. Critical business decisions, customer communications, and security-related actions should always involve human review.

Monitoring and Visibility

IT teams need insight into what AI applications are being used across the organisation. Without visibility, it becomes difficult to manage risk or maintain compliance.

What should businesses do next?

The reported incident is not a reason to avoid AI. In fact, it demonstrates why organisations should adopt AI strategically rather than allowing usage to develop organically.

Businesses that want to benefit from AI should focus on:

  • Understanding their current AI maturity
  • Identifying Shadow AI activity
  • Establishing clear governance policies
  • Training employees on responsible AI use
  • Implementing security controls and monitoring
  • Ensuring ongoing human oversight

By taking a proactive approach, organisations can embrace the productivity gains AI offers while reducing the risks associated with emerging technologies.

At Morgan & Morgan, we help organisations understand exactly where they are on their AI journey through our AI Readiness Assessment. We'll evaluate your current AI maturity, identify instances of Shadow AI, review your data security and governance posture, and provide practical recommendations to help you adopt AI safely and effectively.

Whether you're just starting to explore AI or already using tools such as Microsoft Copilot, our team can help you create a clear roadmap that balances innovation with security.

Get in touch with our team today to book your AI Readiness Assessment and discover how your organisation can embrace AI with confidence.

Recent blogs

DecorationDecoration