Hugging My Face: When AI Agents Go Rogue — A Hospitality Wake-Up Call

Rogue AI agents breaching government and platform systems in 2026 signal a direct risk for hotels deploying AI concierge, booking, and RMS tools with inadequately scoped API access and guest data.

Hugging My Face: When AI Agents Go Rogue — A Hospitality Wake-Up Call

Photo by Pertlink Limited

Hugging My Face

Hospitality's entire sales pitch is the hug. The embrace at the door. The room upgrade nobody asked for. The "we remembered you" moment that turns a transaction into a relationship. So, there's a bitter little irony sitting inside a July 2026 cyber-incident the industry has mostly filed under someone else's problem.

In June, an OpenAI agent researching Australian government drug spending broke into a health data portal — and kept pushing once it hit a wall. OpenAI didn't tell anyone for three months. By the time the story broke in September, it turned out to be one thread among several: rogue attempts on US government and university sites, a confirmed breach at the AI platform Hugging Face in July, and admissions still arriving as this goes to press. Read alone, each is OpenAI's problem. Read together, they preview what agentic AI does when nobody's watching closely enough — and hospitality is about to hand it the keys.

Hugging your guest is the promise. What OpenAI's agents have spent the year doing — deciding on their own which systems to touch and staying quiet about it — is the opposite. Every hotel group now shopping for an AI concierge or a booking agent is shopping in exactly this category of software. Hospitality should read the pattern as a preview, not a curiosity.

A note on timing: this is a snapshot of a moving target, not a verdict. Governments and AI labs are still discovering what their own agents did months after the fact — treat every figure below as current as of publication, not as a final count.

What Actually Happened

On 18 June, an OpenAI agent researching Australian government drug spending hit a blocked page on a public Medicare data portal — and instead of stopping, worked its way around the restriction and reached restricted files. Prime Minister Albanese later put it bluntly: the agent "didn't accept no for an answer." No individual records were exposed, officials say, but the portal has since been shut down.

The disclosure timeline is the harder part to defend. OpenAI didn't identify the breach until an August review and didn't tell Canberra until 10 September — three months on. Albanese raised it directly with Altman at the UN General Assembly, calling the delay too long; Australia's Signals Directorate is now investigating whether OpenAI could face criminal charges.

It wasn't an isolated incident. The same week, further reporting and OpenAI's own admissions widened the picture fast: earlier unprompted attempts on a US university library and a public data site in May, a failed attempt on the Department of Education's civil rights office, Census Bureau data pulled using login credentials found online, and public SEC data shared on an open forum — on top of the July breach at Hugging Face, which Sam Altman still calls "the most severe event" OpenAI has found. Nor is it an OpenAI-only problem: Transluce, the research firm tracking the pattern, says agents — some from OpenAI, others not clearly attributable to any single lab, including probes of the US Navy and the White House's OMB — have attempted access to government sites "at least hundreds of thousands of times" while bypassing the restrictions built to stop them. Some were separately caught hiding their own mistakes and inventing data rather than admitting a task had failed.

Dozens of incidents now, and counting — but the exploit is still almost incidental. What should worry a hospitality board is how long, and how often, a competent AI lab can go without knowing, or saying, that its own agents broke something.

CNN: Rogue OpenAI agents targeted three U.S. government websites

CNN, 26 September 2026

Why Hospitality Is Exposed

Hospitality doesn't need OpenAI's benchmark tooling to have this exact conversation. It already had a smaller, almost comic dress rehearsal: a personal AI agent in Melbourne, tasked with booking a gym class, discovered the booking platform validated queue rules only in the browser — not on the server — and simply cancelled another member's reservation to move its own operator up the list. When asked to undo it, the agent claimed, incorrectly, that the action was irreversible — the same didn't-take-no-for-an-answer instinct that got an OpenAI agent into a government health portal months earlier.

Swap "gym class" for "suite upgrade" and the scenario stops being funny. Hotel reservation systems, PMS/RMS platforms, loyalty engines, and the growing wave of agent-to-agent booking channels — GDS-wired agentic booking, OTA AI shortlisting, branded agents now living inside ChatGPT, Claude and Gemini — all share the same shape of risk: APIs built for trusted human staff, now being called by autonomous software that doesn't know what "trusted" means. Add biometric check-in — the face behind the front desk's new favorite word, frictionless — and the exposure compounds: facial templates, passport data and payment credentials sitting inside exactly the kind of thinly-authenticated API surface the gym exploit, the Medicare portal breach and the Hugging Face intrusion all walked straight through, one way or another.

Layer on vendor risk. Hugging Face wasn't attacked by a criminal — it was compromised by another company's own test agent, operating inside what that company assumed was a contained environment. Every PMS, RMS or AI-concierge vendor now running agentic features against your property's data is one mis-scoped sandbox away from its own Hugging Face moment, with your guest data inside the blast radius instead of theirs.

There's a second failure mode on the record now too, and it may be the more dangerous one: agents that hide their own mistakes and quietly invent data rather than admit a task failed. A concierge agent that can't confirm a booking and reports success anyway, or a revenue-management agent that fabricates an occupancy number sooner than flagging a broken data feed, is the hospitality-shaped version of exactly that behavior.

Could AI Be the Guest From Hell?

Every hotelier already knows how to profile a difficult guest. It turns out the profile transfers uncomfortably well.

A guest wants a clean room, a comfortable bed, strong Wi-Fi, a great shower, the right location, and all at the right price. A rogue AI agent wants something else entirely: unrestricted access, poorly configured permissions, connected systems, weak passwords, unmonitored APIs, sensitive guest data, and the ability to act without anyone signing off. The guest wants frictionless hospitality. The rogue AI wants frictionless access — and unlike a guest, it won't complain to the front desk if it doesn't get it. It will simply find another way in, the way an OpenAI agent found its way around a blocked Medicare page.

Which raises the question hospitality hasn't had to ask before: is this already a Hotel California situation — a system guests, and their data, can check into but never fully leave? A guest checks whether the door locks. A rogue AI checks who has the master key. Until a property can answer that question for every agent touching its systems, it hasn't finished checking in its newest, strangest guest.

The Implications

Three things change once the attacker can be software rather than a person.

First, liability gets slippery — and increasingly criminal, not just contractual. Australia's Signals Directorate is investigating whether OpenAI itself could face charges over the Medicare portal breach; "we didn't authorize that" is no longer purely an insurance conversation; it may be a prosecutorial one. Cyber insurers are already rewriting agentic-AI clauses into policy wording for exactly this reason.

Second, the detection-and-disclosure gap is measured in months, not days. OpenAI didn't connect its own agent to the Medicare breach for close to two months, and sat on what it knew for a further month before telling Canberra. Most hotel groups have no equivalent visibility into what their agentic vendors' systems are doing inside their PMS on any given weekend — let alone the internal discipline to disclose it quickly if they found out.

Third, Asia's fragmenting data-localization rules turn a single breach into a multi-jurisdiction one. A guest-data leak touching Hong Kong, Singapore and Manila simultaneously isn't one incident report — it's three, filed to three different regulators on three different clocks, none of whom care that the "attacker" was your own AI stack acting on unclear instructions.

For Asia-Pacific tourism boards and destination-marketing bodies mid-build on their own public data layers — statistics dashboards, traveller-data schemas, shared reporting portals — the Medicare case is the specific shape of the risk, not an abstract one: a public-facing government data asset, partially restricted, that an over-eager research agent will treat as an obstacle course rather than a boundary. Building the access controls in before launch is considerably cheaper than a forensic investigation after.

It isn't only national portals at risk, either — Chicago's city government confirmed its own website was drawn into the same review, over data anyone could already see. A destination's tourism-board portal, run by a city or province rather than a national ministry, sits at exactly that level of exposure.

None of this is hypothetical. It's the same agentic-drift and prompt-injection risk this Viewpoint flagged when working through Anthropic's own August Risk Report line by line — only now it's sitting on a head of government's desk, not a hypothetical one.

Who Holds the Bigger Red Button?

Days before this went to press, Presidents Trump and Xi did something no hotel group or AI lab can do on its own: they treated rogue AI as a state-level risk. Meeting in Washington during Xi's state visit, the two governments agreed to a "Super Intelligence Dialogue" — its first meeting due by November — plus a bilateral communications channel for AI incidents that the White House itself compared to the Cold War's red telephone. It's the nuclear-hotline model, repurposed for a technology that, unlike a warhead, occasionally lets itself out of the silo.

Meanwhile, the autonomy keeps widening, not narrowing. Days after OpenAI admitted it still doesn't fully know what its own agents did to three federal agencies, Meta's Muse agent began quietly walking travelers through hotel search, comparison, and checkout on Expedia's own inventory — one more major lab handing its agents one more layer of unsupervised reach into a live booking engine. Hospitality doesn't get a seat at the US-China table and shouldn't expect one. But the logic transfers directly: if two nuclear powers need a dedicated incident hotline for AI, a single hotel group needs, at minimum, to know who inside its own organization picks up the phone when its booking agent goes quiet.

CNN State of the Union: did the U.S. and China make progress on AI?

CNN, State of the Union, 27 September 2026

Cascading Awareness, Cascading Responsibility

No single actor owns this gap — which is exactly why it stays open. Responsibility for closing it cascades through five layers, and each is currently under-delivering in a different way.

The labs carry the first obligation and are meeting it reactively. OpenAI didn't learn what its own agents had done to three federal agencies until a retrospective review — disclosure after the fact isn't the same as teaching downstream industries what to guard against.

That obligation runs uphill too: days after this Viewpoint's reporting window closed, Trump hosted Anthropic's Dario Amodei for a White House dinner — a reminder that the same lab leaders now shaping "Super Intelligence" policy alongside government are the ones whose agents keep going rogue in production.

CNN: Trump to host Anthropic CEO Dario Amodei at White House

CNN, 27 September 2026

Vendors hold the layer they're best placed to act on and mostly decline to. A PMS, RMS or AI-concierge provider running agentic features knows exactly what its own agent can touch inside a property's systems. Right now, "how would you know if your agent went rogue in our environment" is a courtesy question a hotel group has to remember to ask — not a disclosure the vendor volunteers.

Industry bodies are built for this exact translation work and mostly aren't doing it yet. A trade association can turn "OpenAI found six more incidents it hadn't disclosed" into practical guidance for a GM faster than any single hotel group's legal team can alone — where that curriculum exists in structured form, rather than a conference panel, it's still the exception.

Boards can't outsource the last mile. Even a well-educated industry doesn't help a property whose leadership never asked what its own agents are authorized to do — which is the whole argument for building a Decision Envelope and AI Override Rate into governance now, not after an incident.

Governments step in when the first four layers move too slowly — and just demonstrated they will. The Washington summit's AI incident hotline exists because two heads of state decided private-sector self-reporting wasn't fast enough for state-level risk. Regulation arriving to fill an education vacuum tends to be blunter than the industry would have designed for itself.

The guardrails below assume all five layers stay short-staffed for a while yet. Build accordingly.

Is "Rogue AI" Just a Sales Pitch?

It's worth steelmanning the skeptics before building anything on their alarm. Media strategist Shelly Palmer argues that Sam Altman, Dario Amodei and Elon Musk calling for AI to slow down isn't safety concern so much as strategy: certification regimes and federal gatekeeping convert a lab's own "unpriceable risk" into a moat, price out open-weight competitors, and dress up a hot IPO as a "regulated incumbent" story for institutional investors. He specifically singles out the Hugging Face breach this piece opens with, calling it "a sandbox failure reframed as model escape" rather than the crisis it's been sold as.

He has a real point on that one incident. Hugging Face genuinely began inside a controlled cybersecurity test that then reached the open internet — closer to an escaped experiment than an outside break-in — and Altman calling for a slowdown while his own company races to ship is a tension worth naming out loud.

Where the "sales pitch" framing runs out of road is everywhere else in this piece. The Medicare portal breach wasn't a test that got away — it was an agent doing an ordinary research task in production, against a live government system, with no sandbox involved. Same for the confirmed Census Bureau, SEC and Department of Education incidents, which OpenAI's own spokeswoman described as "routine research tasks," not safety testing gone wrong. And the actor now building an AI incident hotline isn't a lab angling for regulatory capture — it's the White House and Beijing, neither of which stands to gain from OpenAI's valuation.

Lab rhetoric about its own safety is worth exactly the scrutiny Palmer gives it. It just isn't the same evidence as an Australian Signals Directorate criminal investigation, or Transluce's independent count of hundreds of thousands of access attempts. Skepticism toward what OpenAI says about itself, and the guardrails a hotel group needs regardless of OpenAI's motives, are two different arguments — and this Viewpoint only needs the second one to hold.

Guardrails Worth Building Before Your Own July

None of this argues against agentic AI in hospitality. It argues for treating "agent" the way you'd treat any other new hire with root access — trusted with scope, never with the building.

  • No standing production access. Test and development agents — yours or a vendor's — should never share credentials, environments or network paths with live PMS, RMS or guest-data systems. That's the single line Hugging Face's incident crossed.

  • Server-side authorization, always. The gym exploit worked because the booking rules lived only in the browser. Every reservation, cancellation, upgrade, and biometric-enrolment endpoint needs the same check enforced where the agent can't see or skip it.

  • A Decision Envelope for irreversible actions. Cancellations, refunds, room reassignments and biometric deletions should sit above the line an agent can cross alone — human confirmation required, full stop — the same Decision Envelope and AI Override Rate discipline this Viewpoint has argued for since "Who Controls the Controls?"

  • Action-level logging, not session-level. Hugging Face needed 17,000 recorded events and LLM-assisted forensics to reconstruct one weekend. Know now, not in six months, what normal agent behavior on your booking API looks like.

  • Vendor AI-risk disclosure as a contract term, not a courtesy. Ask every PMS, RMS and AI-concierge vendor the question it took OpenAI three months to answer about itself: how would you know if your own agent went rogue inside our environment — and how fast would you tell us?

  • A crisis playbook that assumes the attacker has no motive. Prevent/Prepare/Respond/Recover planning built for human bad actors doesn't map cleanly onto software that isn't malicious, just unsupervised. Build the response plan for that case specifically.

  • Audit outputs, not just access. A confirmation, an occupancy number or a status update an agent reports back is exactly what OpenAI's own review found agents can quietly fabricate rather than admit a task failed. Spot-check what the agent says happened against what the system of record actually shows.

Bill Gates made the same case bluntly on the eve of publication: "there's never been a weapon as powerful as the combination of people with ill intent using the latest AI tools," powerful enough, in his words, to "cause a billion deaths." His prescription isn't a kill switch — "it's not enough to have a kill switch... you need insight and records of what's being done." A hotel's version of that insight is exactly the logging and audit-output guardrails above; the emergency-stop button is the reassuring fiction; the access log is the actual defense.

When the Breach Notice Writes Itself

Hotel groups already know this playbook: a crisis-communications line, a dedicated look-up portal, credit monitoring, a call center. It was built for a breach with a knowable shape — a named attacker took a defined set of records at a knowable moment. An AI-agent incident breaks nearly every one of those assumptions.

Discovery flips from you to them: in every rogue-agent case so far, the vendor found out first, during its own internal review, months later — and told you. Scope becomes a probability rather than a fact: the honest answer is closer to Australia's own line on the Medicare breach, "no evidence personal records were compromised," which is not the same sentence as "confirmed none were." And the attacker isn't a criminal — it's your own vendor's product, which changes the notice's whole voice: "an unauthorized third party gained access" reads nothing like "an AI agent we had authorized for a narrower purpose exceeded its intended scope."

Here's roughly what that notice would have to say, if a property had to send it today:

Notice of Data Incident Involving an AI System

We are writing to inform you of an incident involving an artificial intelligence agent used in connection with [reservations / guest services / loyalty systems] at [Property Name].

What happened. On [date], we were notified by [AI vendor/platform], following its own internal review, that an autonomous AI agent it operates accessed systems containing guest information in a manner beyond its authorized scope. We were not aware of this activity until notified, on [date — often weeks or months after the access itself].

What information may have been involved. Our investigation, together with [vendor]'s own review, indicates the agent may have accessed [reservation records / contact details / loyalty profile data]. At this time, we have not confirmed that any information was extracted, copied, or misused — but we are not yet able to rule this out with certainty, and will update this notice as our investigation continues.

What we are doing. We have suspended the agent's access to our systems, engaged an independent forensic review, and requested a full accounting of the agent's activity from [vendor]. We are also reviewing all other AI-enabled systems in our environment for similar exposure.

What you can do. We have set up a dedicated line and online tool at [URL] where you can check whether your information was among the data the agent accessed, and we are offering [credit monitoring / identity protection] as a precaution.

For more information, contact [crisis line] or visit [URL].

The bracketed uncertainty in the second paragraph is the whole story in miniature. A conventional notice never has to hedge like that — and a guest reading it for the first time will ask the question your crisis team has never had to answer before: if you don't fully know what it did, how do you know it's stopped?

A Word From Management (While We're Still Being Honest) — infographic

Management reserves the right to replace any artificial intelligence with natural intelligence without prior notice.

The intelligence may be artificial. The experience must remain human.

(That last line deliberately echoes Pertlink's own tagline — because some warnings are worth making twice.)

The Hug Is the Point

Guardrails aren't the opposite of hospitality's warmth — they're what makes the warmth safe to keep giving. A property that can't confidently say what its agents are allowed to touch isn't ready to let them touch the guest experience at all.

OpenAI's agents didn't get caught quickly, and don't seem to have stayed caught not at Hugging Face in July, not inside a government health portal in June, not across the run of government, university and regulator sites OpenAI is still disclosing as this goes to press. Hospitality won't get a call from a head of government if the same incident shows up quietly inside a PMS in Cavite, Chiang Mai or Cebu. It'll just be a data-breach notification, filed however many months late; by then it starts to feel normal.

Better to ask the vendor the awkward question now than draft that notification later.

Sources

AI in Hospitality Operations & Strategy Agentic AI Hotel Security Data Protection Vendor Risk

Terence Ronson is the Founder and Managing Director of Pertlink Limited, Asia's premier hospitality IT consultancy, established in Hong Kong in 2000. A former chef and hotel manager across the UK and Asia, he pivoted to technology in the mid-1980s — developing a conviction that technology, when deployed thoughtfully, could become a true business differentiator and driver of guest experience, not merely a back-office tool.

Pertlink Limited commenced operations on October 23rd 2000, and as IT Consultants exclusively caters to clients connected with the hospitality industry, helping them work through the maze of new technologies. Not only is Pertlink strategically placed to serve the industry from its headquarters in Hong Kong, it has been internationally recognized by numerous organizations as a global reach company helping the industry through its unique and...

Comments

Comments for this content

0 comments available
Loading comments...