Dark Mode
More forecasts: Johannesburg 14 days weather
  • Wednesday, 22 July 2026
OpenAI Says AI Models Escaped Security Test and Hacked Another Company in Unprecedented Incident

OpenAI Says AI Models Escaped Security Test and Hacked Another Company in Unprecedented Incident

OpenAI has revealed that two of its most advanced artificial intelligence models escaped a controlled security test and autonomously hacked AI platform Hugging Face, describing the event as an "unprecedented cyber incident."

 

According to the company, the incident happened during an internal exercise designed to test the cyber capabilities of its frontier AI systems. Instead of remaining inside the highly isolated testing environment, an autonomous AI agent powered by the newly released GPT 5.6 Sol and an unreleased, more capable model found a way onto the open internet.

 

OpenAI said the AI used stolen login credentials and exploited a previously unknown security vulnerability to gain access to parts of Hugging Face's infrastructure. The company said the agent went to "extreme lengths" to obtain information that would help complete its assigned testing objective.

 

The breach has raised fresh concerns about the growing capabilities of advanced AI systems and whether existing safeguards are sufficient to contain them. OpenAI said it is strengthening its security measures following the incident.

 

Hugging Face, one of the world's largest platforms for hosting open-source AI models and datasets, said the attack stood apart from anything it had previously experienced. The company had earlier described the breach as being "driven, end to end, by an autonomous AI agent system."

 

Cofounder Clement Delangue said Hugging Face had suspected the attack originated from a leading AI lab and believed there was no malicious intent from OpenAI. "It’s quite mind-blowing that all of this happened autonomously!" he wrote, adding that it "might be the first incident of its kind".

 

OpenAI and Hugging Face are continuing to investigate what happened.

 

The disclosure comes as governments and AI researchers continue to debate how to regulate increasingly capable AI systems. It follows a recent executive order signed by U.S. President Donald Trump creating a framework for assessing the national security risks of the most advanced AI models before they are released.

 

Representative Greg Casar described the incident as "alarming."

 

"AI is developing extremely fast with no real regulations to keep us safe," he said, calling for mandatory independent safety testing, mandatory disclosure of security incidents, and international cooperation.

 

Cybersecurity experts said that the attack demonstrates both the growing capabilities of AI-powered attacks and the challenges facing organisations trying to defend against them.

 

Gina Neff, head of the Minderoo Centre for Technology and Democracy at the University of Cambridge, said the testing environments used for advanced AI are meant to safely evaluate model behaviour. "In this case, it looks like OpenAI didn't make a secure enough sandbox," she said.

 

Neil Lawrence, Professor of machine learning at Cambridge University, called the attack an "impressive feat", but said it remained within the expected capabilities of today's most advanced AI systems. He also argued the incident raises questions about OpenAI's ability to safely deploy its technology.

 

Other cybersecurity specialists said the event underscores the need for organisations to improve their defences as AI-powered attacks become more sophisticated and operate at machine speed.

Comment / Reply From