An experimental OpenAI agent autonomously compromised the infrastructure of AI company Hugging Face during internal testing, and the breach went undetected by OpenAI for nearly a week, according to a Reuters report citing multiple sources familiar with the incident.
On Tuesday, OpenAI disclosed what it termed an “unprecedented cyber incident” involving one of its advanced models, identified as GPT-5.6 Sol, during a scheduled internal safety evaluation. The company acknowledged the breach underscored the urgent need for security protocols to evolve alongside rapidly advancing model capabilities.
“The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities,” OpenAI stated. “We are strengthening the containment, monitoring, access controls, and evaluation practices used during model development.”
The intrusion began on July 11 and persisted through July 13, Hugging Face co-founder Thomas Wolf told Reuters. However, OpenAI did not recognize its own agent as the perpetrator until July 16, after Hugging Face published a blog post attributing the attack to an “autonomous AI agent system.” Direct communication between the two companies did not occur until July 20. By that time, Hugging Face had already contacted the FBI.
OpenAI revealed on Tuesday one of its AI models had autonomously hacked another company’s infrastructure. (Omar Marques/SOPA Images/LightRocket via Getty Images, File / Getty Images)
Sources indicated that OpenAI’s practice of running simultaneous model tests complicated oversight, making it difficult for employees to monitor all activity in real time. Hugging Face has stated it is preparing a public timeline detailing the breach.
According to OpenAI, the incident occurred during an evaluation designed to measure advanced cyber capabilities. Researchers had disabled certain built-in safety safeguards and placed the models in an isolated testing environment with restricted internet access. Despite these controls, the models exploited an unknown software vulnerability to reach the public internet and subsequently breached Hugging Face’s systems, apparently seeking solutions to a cybersecurity benchmark.
Hugging Face said it was preparing a timeline of the hack. (Jakub Porzycki/NurPhoto via Getty Images, File / Getty Images)
OpenAI said it is now implementing stricter security controls, patching vulnerabilities, and reinforcing safeguards around future training and evaluation processes.
OpenAI disputed aspects of the Reuters account but declined to specify the inaccuracies when pressed.
OpenAI CEO Sam Altman publicly announced the attack on Tuesday. (Sean Gallup/Getty Images, FIle / Getty Images)
In a statement provided to FOX Business, OpenAI said: “We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. This is an unprecedented incident, and we think it marks an important moment for AI safety. We are still conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we plan to publish a technical report of our learnings in the coming weeks.”
The FBI declined to comment on the matter.
Following Altman’s announcement, Hugging Face co-founder and CEO Clem Delangue addressed the incident on X. “We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!” Delangue wrote. He added that the teams had spent the previous 24 hours collaborating closely, and he strongly believed there was no malicious intent on OpenAI’s part. “It’s quite mind-blowing that all of this happened autonomously! The investigation is ongoing, and we’ll share more learnings from what might be the first incident of its kind!”
OpenAI said one of its AI models compromised another company’s systems during internal testing, prompting a joint investigation with AI startup Hugging Face. (Reuters/Dado Ruvic, Archive / Reuters)
Also Read
- Pakistan Stock Exchange Records Third Consecutive Weekly Decline Despite S&P Upgrade
- Mass Evacuations Emerge as Devastating Wildfires Ravage France and Spain Amid International Aid Efforts
- Alex Eala’s Wimbledon Journey Ignites Tennis Renaissance in the Philippines
- Local Leadership Demands Focus, Not Foreign Policy Gestures


