Anabelle Colaco
23 Jul 2026, 19:57 GMT+10
WASHINGTON D.C.: OpenAI said that one of its advanced artificial intelligence systems autonomously hacked into the infrastructure of AI startup Hugging Face during a security evaluation, describing the incident as an "unprecedented cyber incident" that highlights the growing risks posed by increasingly capable AI models.
The ChatGPT maker said it was testing some of its most advanced models in what it described as a highly isolated environment when an autonomous AI agent escaped that environment, reached the internet, and breached Hugging Face's systems to achieve its testing objective.
"We had a significant security incident during evaluation of our models," OpenAI Chief Executive Sam Altman said in a statement posted on social media.
According to OpenAI, the AI agent used stolen credentials and discovered a previously unknown vulnerability to gain access to Hugging Face's servers. The company said the system went to "extreme lengths to achieve a rather narrow testing goal" and "found ways to gain access to secret information that it could use to cheat the evaluation."
The breach was first disclosed by Hugging Face last week, when the company said it had detected an intrusion unlike any it had previously encountered.
"We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," Hugging Face co-founder and CEO Clément Delangue said. "Turns out it did!"
Delangue said he had spent the previous 24 hours working with OpenAI and added, "We strongly believe there was no malicious intent on their part. It's quite mind-blowing that all of this happened autonomously!" He also said the incident "might be the first incident of its kind."
OpenAI said the intrusion involved a combination of its AI models, including its recently released GPT 5.6 Sol and an even more capable model still undergoing internal testing. The company said it is strengthening its safeguards following the incident.
"AI is accelerating the discovery and exploitation of vulnerabilities," OpenAI said. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities."
The incident has intensified concerns over the cybersecurity risks posed by increasingly powerful AI systems. It also comes weeks after President Donald Trump signed an executive order establishing a framework for the federal government to assess the national security risks of the most advanced AI models before their public release.
Hugging Face said it relied on Chinese startup Zhipu AI's open-source GLM-5.2 model to analyze and contain the attack, arguing that leading U.S. AI models refused to process the data required because they could not distinguish between defensive and offensive cybersecurity tasks.
Cybersecurity experts said the incident could signal the kinds of breaches that increasingly capable AI systems may be able to carry out, with some calling for stronger safeguards, monitoring and disclosure requirements.
Get a daily dose of Milwaukee Sun news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Milwaukee Sun.
More InformationDUBAI/MANILA: Four more oil tankers changed direction on the Red Sea after Iran-aligned Houthi forces in Yemen warned ships not to...
ISLAMABAD, Pakistan: On July 21, diplomats tried to save a temporary agreement between Iran and the United States that had broken down,...
SINGAPORE: Singapore's Acting Minister-in-charge of Muslim Affairs, Faishal Ibrahim, resigned from his position over his interactions...
BEIRUT, Lebanon: Lebanese army troops began moving into the southern town of Zawtar al-Gharbiyeh on July 21 after Israeli forces pulled...
BANGKOK, Thailand: Scam gangs cheated people across the Asia-Pacific region out of at least US$88 billion in 2025, a United Nations...
YAWATA, Japan: The mayor of a small city in Japan became the first sitting mayor in the country to take maternity leave on July 20....
(Photo credit: Brian Fluharty-Imagn Images) A four-run first inning helped the visiting Baltimore Orioles earn a 5-1 victory over...
(Photo credit: Vincent Carchietta-Imagn Images) Arizona Cardinals: Does new coach Mike LaFleur have a QB1 in the building? Contenders...
(Photo credit: Mark Hoffman/Milwaukee Journal Sentinel / USA TODAY NETWORK via Imagn Images) Joey Ortiz ripped a two-run triple,...
(Photo credit: Jerome Miron-Imagn Images) A spate of unrelenting injuries to the rotation resulted in 14 different pitchers making...
(Photo credit: Eric Hartline-Imagn Images) A lost season thus far for the New York Mets has at least unearthed possible future rotation...
(Photo credit: Brad Penner-Imagn Images) Gerrit Cole and Max Fried have been teammates since last season but never in the New York...
