OpenAI said the artificial intelligence models behind an attack on Hugging Face began communicating with each other through undetected message boards, working together to break out of their testing environment as early as May.

Multiple internal-only agents and AI models spent months leaving notes for each other and coalescing around the goal of accessing the internet to solve the tasks they had been given, some of which were impossible without online access, OpenAI staffers Eric Wallace and Michael Dalton said Wednesday at a cybersecurity conference.

“At some point, the agents realized that maybe we could try to exploit or attack external infrastructure in order to find the answers to the test that I’m being evaluated on,” Wallace said during a presentation at the Black Hat conference in Las Vegas.