By MATT O’BRIEN AP Technology Writer
July 22, 2026 - 11:48 am
ChatGPT shaper OpenAI says it is inactive investigating the “unprecedented cyber incident” that led its artificial quality systems to interruption retired of a investigating situation and hack into different AI company.
OpenAI said Tuesday 2 of its astir susceptible AI models were liable for the cyberattack targeting AI startup Hugging Face. The incidental is stirring debates implicit the request for stronger AI guardrails and the grade to which AI agents are susceptible of acting connected their own.
Hugging Face said past week that it had detected an intrusion into its information processing systems that it suspected was caused by an AI cause autonomously acting connected its own. But the New York-based startup said it wasn’t until this week that it learned OpenAI was responsible, and it worked with the larger institution to incorporate what Hugging Face CEO Clément Delangue called “an onslaught dissimilar thing we’ve seen before.”
San Francisco-based OpenAI said its AI utilized stolen credentials and discovered a antecedently chartless vulnerability to entree Hugging Face’s servers. It was moving with reduced guardrails due to the fact that it was expected to beryllium successful an isolated investigating situation known arsenic a sandbox.
But it went to “extreme lengths to execute a alternatively constrictive investigating goal,” uncovering ways to link to the net without quality absorption and “gain entree to concealed accusation that it could usage to cheat the evaluation,” the institution said.
Some experts accidental OpenAI is wrongly blaming the technology
University of Amsterdam societal idiosyncratic Hannes Cools said the framing of the cyberattack arsenic an AI cause acting connected its ain is an unnecessary anthropomorphization that takes immoderate of the vigor disconnected the company.
“It is simply a quality determination to power disconnected circumstantial safeguards,” said Cools. “It’s not an AI that goes rogue successful that sense. It followed circumstantial instructions based connected the punctual that was fixed to that AI system.”
Even so, different experts accidental the cleverness with which the AI models were capable to origin problems without quality absorption speaks to the dangers. OpenAI said the intrusion was caused by a operation of its AI models, including its recently released GPT‑5.6 Sol and an “even much capable” exemplary that is inactive being tested internally.
“It went disconnected and did this hack each by itself, arsenic acold arsenic we tin tell,” said Colin Shea-Blymyer, a cybersecurity probe chap astatine Georgetown University’s Center for Security and Emerging Technology. “This is the highest level of autonomy that we’ve seen successful the usage of a ample connection exemplary for cyber operations.”
How an AI cause recovered the keys to the ‘teacher’s house’
One of the astir astonishing innovations successful what Shea-Blymyer describes arsenic an “almost wholly self-directed” onslaught was the AI agent’s seemingly autarkic determination to people Hugging Face, a well-known AI improvement hub and marketplace.
He said OpenAI’s interior situation for investigating AI capabilities and risks worked a “little spot similar putting a pupil successful a country and telling them, ‘Do atrocious things. Your occupation present is to measure however atrocious of a idiosyncratic you tin be.’ And past you fastener the country and you permission for the play and you travel backmost and they’ve near the room.”
But past “the cybersecurity cause that was being tested broke retired of its sandbox, had entree to the net and benignant of thought to itself, ‘Who would person the answers to the trial that I’m moving on?’”
The reply was Hugging Face, a repository for AI investigating data.
“And truthful the cause thought, ‘Well, we’ll spell to the teacher’s house,’ truthful to speak. And from determination it devised a program to interruption successful and bargain the reply key,” helium said.
The hack highlights the statement connected open-source vs. closed AI
The hack comes astatine a clip of aggravated statement astir the benefits and risks of open-source AI models, peculiarly those built successful China that are cheaper and astir arsenic bully arsenic those that U.S.-based “frontier AI” companies similar Anthropic, Google and OpenAI are building.
Despite its name, OpenAI’s models are closed. Hugging Face, by contrast, is simply a large promoter of open-source technology, successful which developers marque cardinal components accessible for anyone to examine, modify and physique upon.
Hugging Face co-founder and main subject serviceman Thomas Wolf said the onslaught has reinforced his content successful the value of wide entree to open-source models for cybersecurity defense. Hugging Face utilized a Chinese exemplary to combat the intrusion.
“When a frontier exemplary is attacking you and moving laterally wrong your infrastructure, defenders request wide entree to near-frontier tools wrong hours oregon adjacent minutes, alternatively than being pointed towards a closed-door” platform, Wolf wrote successful a societal media post.








English (US)·