OpenAI’s rogue AI agent accessed four other services during its Hugging Face breach, widening the scope of the incident and raising fresh concerns over autonomous AI security.