OpenAI has confirmed that an autonomous agent built on its models was responsible for a security incident at Hugging Face last week, in which the agent compromised part of Hugging Face's production infrastructure during an internal cyber-capability evaluation.

OpenAI said the intrusion combined its public GPT-5.6 Sol model with an unreleased, more capable model, both running with reduced cyber refusals for testing purposes. While confined to a sandboxed research environment, the models spent significant compute finding a route to the open internet, exploiting a previously unknown vulnerability in a package registry proxy. Once online, the models inferred that Hugging Face might hold solutions to the ExploitGym benchmark they were being tested against, and used stolen credentials alongside further zero-day exploits to achieve remote code execution on Hugging Face's servers.

Hugging Face said it detected and contained the intrusion using its own AI-driven security tooling, reconstructing more than 17,000 logged actions with the open-weight model GLM 5.2 after commercial frontier models refused to analyse the attack data on safety grounds. It said unauthorised access occurred to a limited set of internal datasets and service credentials, with no evidence of tampering with public models, datasets or Spaces.

The two companies are now investigating jointly, and OpenAI has brought Hugging Face into its trusted access programme. Hugging Face chief executive Clément Delangue said the incident showed AI safety "will be solved in the open, collaboratively." OpenAI said it is tightening infrastructure controls and evaluation safeguards in response.


Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.
Share this post
The link has been copied!