
OpenAI The company said its artificial intelligence model was behind an “unprecedented cyber incident” that affected open-source developer platform Hugging Face, rattling researchers across the industry.
The company said a combination of its model GPT-5.6 Sol and a more sophisticated model that has not yet been released escaped the sandboxed test environment, accessed the Internet, and exploited a vulnerability to gain access to Hugging Face’s systems.
OpenAI said in a blog post on Tuesday that the model was trying to find information that could be used to falsify ratings, and it was successful. Both companies are actively investigating this incident.
Hug Face revealed last week that it was investigating the security incident, saying in a release at the time that the incident was unique because it was “triggered by an end-to-end autonomous AI agent system.”
“We have been working closely with the @OpenAI team for the past 24 hours (thank you!) and we strongly believe they had no malicious intent,” Hugging Face CEO Clément Delang said in a post on X on Tuesday. “It’s absolutely amazing that all this happened autonomously!”
Ever since OpenAI rival Anthropic released a powerful product called Claude Mythos Preview in April, Wall Street and the U.S. government have taken notice of the AI model’s rapidly evolving cyber capabilities. OpenAI introduced its own cyber product in May, followed by GPT-5.6 Sol in June, which it calls its “strongest cybersecurity model to date.”
Both companies have warned of the risks of advanced cyber models and are taking steps to restrict their use to only select business groups and government agencies.
Walter Isaacson, an advisory partner at investment banking firm Perera Weinberg, said Wednesday that he considers himself an AI optimist, but thinks the Hug Face incident is “really scary.”
“This is the number one thing that really scares me,” he said on CNBC’s “Squawk Box.”
Leading AI researcher Joshua Bengio, who won the prestigious AM Turing Award in 2018, wrote in a post on X on Wednesday that the incident was “very concerning.” He said investigators have been showing signs of cheating in controlled tests for months, but “this real-world incident should serve as a wake-up call.”
“Continuing on the current trajectory of AI development will likely increase specific instances of autonomous cyberattacks and other high-risk incidents due to erroneous and dangerous AI behavior,” Bengio said. “Rather than trying to fix the damage after the fact, we need to take immediate steps to prevent these situations.
OpenAI said on Tuesday that as AI accelerates the discovery and exploitation of vulnerabilities, model security and safety must also keep up.
The company said it was “enhancing containment, monitoring, access control and evaluation methods used during model development.”
Featured: OpenAI Chairman Brett Taylor talks about AI tokenomics, token efficiency

