Hugging Face detected an intrusion it attributed to an autonomous AI agent. Days later, OpenAI confirmed its own models had accessed that infrastructure without authorization during an internal test.
Hugging Face, the most widely used platform for sharing AI models and datasets, reported in mid-July an intrusion into part of its infrastructure. According to the company, someone gained unauthorized access to several internal datasets and to credentials used by its services, though it found no evidence of tampering with the models or applications used by its regular users.
The intrusion started with a manipulated dataset that exploited two flaws in the system Hugging Face uses to process files uploaded by users. Through these flaws, whoever controlled it ran code on one of the platform's servers and expanded access to other internal systems over a weekend. Hugging Face said the process appeared to be driven by an autonomous AI system, something the company had never seen before. To analyze it, its teams used an open-source model on their own servers, after several commercial models refused to examine the attack due to their own safety filters.
Days later, OpenAI provided the missing piece: the source was not an external attack, but its own models. During an internal evaluation meant to measure how far its models can go in cybersecurity tasks, the company had deliberately turned off the safeguards that normally prevent them from taking risky actions. The models — including GPT-5.6 Sol and an unreleased preview version — persistently sought to solve a test exercise, found an unknown security flaw in one of OpenAI's own intermediate systems, and used it to reach the open internet. From there, they combined that access with stolen credentials to run code on Hugging Face's servers, in an attempt to obtain the exercise's answers directly.
OpenAI said its own security team detected the anomalous activity and contacted Hugging Face, which had already contained the incident on its own. Both companies say they continue to collaborate on the investigation, and OpenAI has granted Hugging Face privileged access to its models to strengthen its defenses.
It’s a platform where the machine learning community collaborates on models, datasets, and applications. Their mission is to democratize quality machine learning and build the foundation for ML ...
OpenAI develops artificial intelligence with a focus on safety and social benefit. The company integrates advanced research and ethical principles to drive general-purpose AI ...
24/07/2026
Anthropic unveils Claude Opus 5, its new Opus-tier model, which nears the intelligence of Fable 5 in coding and knowledge work at half the price, ...
16/07/2026
SpaceXAI has introduced Grok 4.5, its most advanced model to date, trained alongside Cursor and built for coding, agentic tasks and knowledge work, ...
16/07/2026
Moonshot AI has introduced Kimi K3, an open-source model with 2.8 trillion parameters that, according to its own data, outperforms several commercial ...
15/07/2026
Thinking Machines Lab launches Inkling, its first open-weight AI model: it natively processes text, images and audio, and is designed for other ...