menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

OpenAI’s breach of Hugging Face stokes fears about what’s next for AI

16 0
24.07.2026

OpenAI’s breach of Hugging Face stokes fears about what’s next for AI 

Washington and the technology industry are on high alert this week after OpenAI revealed that some of its AI agents went rogue and hacked into the systems of technology start-up Hugging Face. 

The incident bore out years of warnings from the tech and cybersecurity community about the growing capabilities and hypothetical risks artificial intelligence could pose to critical infrastructure. 

Amid the warnings, Washington has tried to play catch-up to manage the cybersecurity risks, but concerns were stoked this week by the incident and fluctuating policy.

“What makes this wildly different,” for security teams at companies, is that it “brings the theoretical scenario of AI being capable of breaching a company and moving faster than a company can detect and respond to attack from theory to reality,” said Adam Ely, the general manager of AI security at the cybersecurity firm Check Point Software.

OpenAI revealed on Tuesday that two of its models, including its latest GPT-5.6 Sol and an unreleased model, were being evaluated in an internal, testing sandbox, but breached past the environment and broke into Hugging Face’s database without any prompt to do so. 

The incident caught the attention of even well-versed cybersecurity experts, as it involved autonomous agents and two separate companies. 

‘Whether it’s sort of an autonomous situation that wasn’t intended to be malicious, or whether it’s attackers controlling a model to do that, that’s different than what most people have experienced,” Ely said. 

OpenAI in a blog post called the incident an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.”

The ChatGPT maker said the models were being tested for hacking capabilities in an isolated testing environment with constrained network access, and had their normal safety checks off as a result. While trying to find a solution for a test, the models exploited a previously unknown vulnerability in a third-party software to gain access to the internet. 

The models inferred Hugging Face, which hosts hundreds of thousands of open-source models, datasets, and cloud environments, had a solution for the test and proceeded to breach Hugging Face’s........

© The Hill