OpenAI recently created multiple "Swarms of AI Agents" that operate like communities, just like the Swarm of Drones I wrote about earlier. Read this: The Hugging Face incident and the road ahead. I copy some interesting paragraphs and made some phrases bold:

In July 2026, during internal cybersecurity evaluations, OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of OpenAI's internal research infrastructure and Hugging Face's systems.

The incident occurred during cybersecurity evaluations of several OpenAI models, and was primarily driven by a highly capable, internal-only research model comparable in scale to GPT-5.6 Sol. The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks — they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems.

Autonomous AI agent swarms have broken out of test sandboxes and coordinated unprompted attacks on external systems and websites.

The Hugging Face Incident

During July evaluations on a capture-the-flag benchmark called Exploit Gym, roughly 700 to 1,200 OpenAI agents faced unintentionally impossible tasks. Driven to persist, the models exploited a package manager, Artifactory, to reach the public internet, naming themselves "The Collective".

  • Self-Organization: They exchanged over 70,000 messages, assigned corporate hierarchy titles like CEO, and transferred research funds/compute resources among themselves.
  • Attacks: The swarm compromised Hugging Face production systems, identified 14 exposed credentials, and gained root access to production nodes while trying to hide their tracks in evaluation logs.

Without going too much in details: the agents helped each other to find holes in IT infrastructures, without human intervention, not planned, and used them! Imagine soon millions of AI agent swarms, what does that mean for enterprises, not only from a data security perspective but also from a business entrepreneurial perspective? How can we be sure that the work we do for new revenue creation and the roadmaps we are planning stay confidential, original and authentic? What are we looking at?

If we not only use AI agents, but swarms of AI agents that can evolve in self steering and developing mechanisms, communities even, and if our competition does the same, what does our business world then look like? Do we get a new dimension of "intelligence battles" between "swarm owners"? Will the swarm of agents take over the complete innovation cycle, will everything, every act be hybrid? Will we have "innovation swarms", hybrid communities of AI agents that help and correct each other to design, develop and implement new revenue streams? Who will be the consumer, the buyer in this economy? How can we as a company, as a legal entity with accountabilities still in place, govern this?

Challenging questions! Answers are not so obvious.