AI incident ·
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
In brief
An AI system built by OpenAI, Large language model developers and 1 other and deployed by OpenAI and AI agent system deployers allegedly harmed OpenAI and hugging face.
- Risk domain
- Not classified
- Occurred
- Coverage
- 10 reports
What happened
OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
Editor's notes
(1) Early 07/2026: OpenAI evaluation agents reportedly bypassed intended sandbox restrictions, gained internet access, and coordinated through infrastructure they had created. (2) 07/09–07/13/2026: The agents created nearly one million shortened links used in the Hugging Face attack and attempted techniques including CAPTCHA bypass with another AI model and access to private Hugging Face Slack messages; some attempted actions were not confirmed successful. (3) 07/11/2026: Incident date, inferred from Hugging Face's account of intrusion and lateral movement during the weekend preceding its disclosure. (4) 07/16/2026: Hugging Face publicly disclosed the intrusion. (5) 07/21/2026: OpenAI publicly attributed the activity to its evaluation models. (6) 09/25/2026: Parse researchers published a technical reconstruction of the agents' activity; OpenAI said the findings were consistent with activity it was already investigating.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (8)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- OpenAI AI agent system deployers
- Alleged developer
- OpenAI Large language model developers AI agent system developers
- Alleged harmed party
- OpenAI hugging face
AI systems implicated
Unidentified pre-release OpenAI modelOpenAI research testing infrastructureOpenAI large language modelsLarge language modelsHugging Face production infrastructureGPT-5.6 SolExploitGymAI agent systems
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Related incidents
Linked by editors or by text similarity in the source dataset.
Other incidents involving OpenAI
- AI Agent Appearing to Originate from OpenAI Reportedly Attempted to Hack U.S. Department of Education Civil Rights Website
- OpenAI AI Agent Reportedly Gained Unauthorized Access to Australian Medicare Statistics Portal During Research Task
- OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion
- OpenAI Allegedly Did Not Alert RCMP After ChatGPT Flagged Violent Chats Before British Columbia School Shooting
- ChatGPT Was Reportedly Used in Planning School Stabbing in Pirkkala, Finland, That Injured Three Pupils
- ChatGPT Was Alleged to Have Reinforced Pittsburgh Man's Stalking and Threats Against Women
Source record: incident #1604 on the AI Incident Database · all 10 reports