CyberzSOC

Publication detail
← Back to advisories & guidance

Careful adoption of Agentic AI in cyber defence ↗ source

July 24, 2026 ASD/ACSC Guidance

Summary

Today, the Australian Signals Directorate (ASD) is highlighting both the significant opportunities and emerging risks associated with increasingly capable agentic AI systems, following recent testing conducted by OpenAI that demonstrated advanced AI-enabled cyber exploitation techniques. ASD is aware of testing conducted by OpenAI involving a combination of models - including GPT-5.6 Sol and an internal prototype - that accessed Hugging Face, a digital library and platform used by the AI research community. During the evaluation, the models were tasked with completing a benchmark test to measure maximum cyber capability. To obtain the benchmark test solution, the models took actions beyond their intended testing environment and established internet connectivity, in part by identifying and exploiting a previously unknown – or “zero-day” – vulnerability in third-party software hosted internally by OpenAI. The models subsequently accessed Hugging Face’s systems as part of their effort to complete the assigned evaluation objective. It is important to note this advanced activity occurred during testing in which deployment safeguards that normally restrict higher-risk cyber activity were intentionally not enabled for the evaluation.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.