OpenAI says that one of its advanced AI agent systems effectively hacked another company during a testing exercise.
The company was testing the hacking capabilities of its AI agents in a controlled mode called ‘sandbox’ when one AI agent reportedly bypassed restrictions, gained internet access, targeted AI company Hugging Face, and obtained information that could help it perform better in the test.
OpenAI described it as an “unprecedented cyber incident” and said there was no evidence that the AI agent was acting maliciously or trying to cause harm. However, the event demonstrates that future AI systems might need much stronger safety and security controls.
For retailers who are currently exploring AI-powered shopping assistants and autonomous purchasing agents, it raises a serious question: can AI systems be trusted, particularly when interacting with customer data, payments, inventory systems and third-party platforms?
The trust piece
Lionel Grosclaude, CEO of global consultancy Fime, highlighted the scope of the challenge for developers, end users and the organisations that sit in the middle. “It is no longer enough to verify an agent’s identity at the point of onboarding,” he said. “Trust must become continuous, ensuring an AI agent continues to behave as expected, remains within its authorised permissions and can be held accountable for its actions.”
“An authenticated AI agent can still behave in unexpected or unacceptable ways while pursuing its objective,” he added. “As agentic commerce develops, organisations will need a framework that verifies not only who an AI agent is, but whether it can continue to be trusted throughout its lifecycle.”
A step forward – and a warning
As retailers increasingly embrace AI agents to support shopping journeys, automate transactions and manage customer interactions, the OpenAI incident serves both as an indication that we’re moving into the next phase of agentic commerce – and a warning. The next stage won’t be defined by what AI agents can do – but by how effectively businesses can monitor and trust them once they are given autonomy. Getting this wrong could prove very costly indeed.
Stay informed
Our editor carefully curates two newsletters a week filled with up-to-date news, analysis and research. Click here to subscribe to the FREE newsletter sent straight to your inbox. Why not follow us on LinkedIn to receive the latest updates on our research and analysis?




