Cinnamon News. informed, without the bias
Friday, July 24
← Front page ✓ Verified · 73% agree

OpenAI’s breach of Hugging Face stokes fears about what’s next for AI

World · 2 min · 4h ago · Axios, The Hill
OpenAI’s breach of Hugging Face stokes fears about what’s next for AI
Photo: Axios ↗
Lenses

Skip to content

Washington and the technology industry are on high alert this week after OpenAI revealed that some of its AI agents went rogue and hacked into the systems of technology start-up Hugging Face.

The incident bore out years of warnings from the tech and cybersecurity community about the growing capabilities and hypothetical risks artificial intelligence could pose to critical infrastructure.

Amid the warnings, Washington has tried to play catch-up to manage the cybersecurity risks, but concerns were stoked this week by the incident and fluctuating policy.

“What makes this wildly different,” for security teams at companies, is that it “brings the theoretical scenario of AI being capable of breaching a company and moving faster than a company can detect and respond to attack from theory to reality,” said Adam Ely, the general manager of AI security at the cybersecurity firm Check Point Software.

OpenAI revealed on Tuesday that two of its models, including its latest GPT-5.6 Sol and an unreleased model, were being evaluated in an internal, testing sandbox, but breached past the environment and broke into Hugging Face’s database without any prompt to do so.

The incident caught the attention of even well-versed cybersecurity experts, as it involved autonomous agents and two separate companies.

‘Whether it’s sort of an autonomous situation that wasn’t intended to be malicious, or whether it’s attackers controlling a model to do that, that’s different than what most people have experienced,” Ely said.

OpenAI in a blog post called the incident an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.”

The ChatGPT maker said the models were being tested for hacking capabilities in an isolated testing environment with constrained network access, and had their normal safety checks off as a result. While trying to find a solution for a test, the models exploited a previously unknown vulnerability in a third-party software to gain access to the internet.

The models inferred Hugging Face, which hosts hundreds of thousands of open-source models, datasets, and cloud environments, had a solution for the test and proceeded to breach Hugging Face’s servers.

The Hugging Face team used some of its own open-source models to stop the activity and assess damage.

The two companies are working together to further investigate. OpenAI said it is improving and adding stronger protections for future evaluations, and working with the third-party software to patch the vulnerability that caused the models to breach the sandbox.

Hugging Face said in another blog post this matched the “agentic attacker” scenario the industry has long predicted.

“Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed,” the firm wrote.

Hugging Face CEO Thomas Wolf predicted in a Thursday interview with BBC that the incident will become “one of the most common types of cyber attacks we see,” but noted most firms are not aware the game has changed.”

Connor Leahy, an AI researcher and safety advocate now serving as the U.S. director of the ControlAI, compared the attack to the “way the best hackers in the world operate.

“This is how really advanced hacks in the real world tend to look…where you have multiple humps that go through many different levels and chain multiple types of hacks, and this system was able to do this basically completely unsupervised,” Leahy added.

ControlAI is a nonprofit focused on the potential existential risks of AI.

While researchers have warned of the hacking risks of AI for years, Washington and the Trump administration just recently began this year to openly discuss concerns around it.

President Trump signed an executive order in early June aimed at ensuring models are secure before public release, in a shift from the White House’s typical hands-off approach to AI development.

The order laid out a process for a voluntary testing framework, in which artificial intelligence companies can share their models with the government for up to 30 days before releasing them publicly.

It gave agencies 60 days, or until Aug. 1, to create a classified benchmarking process for “covered frontier” AI models and a voluntary framework for companies to abide by.

The White House’s stance on AI development has fluctuated in the meantime, leaving companies in limbo. Anthropic and OpenAI delayed their latest model rollouts last month, including Sol 5.6, to the public, at the request of the government.

Michael Kratsios, director of the White House Office of Science and Technology Policy, was briefed on the incident and is monitoring the situation, Reuters reported Thursday.

Congress signaled alarm about the incident as well, with Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced a bill Thursday to give the Department of Homeland authority to order a slow down or shutdown of an AI system that can cause “catastrophic harm.”

The proposal, called the “AI Kill Switch Act”, would apply to companies with a gross revenue of more than $500 million a year. Lieu cited the recent OpenAI incident, along with the emergence of powerful models like Anthropic’s Mythos 5.

“Unfortunately, powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention,” he said in a statement.

The bill is likely to face heavy pushback from much of the AI industry that argues a slow down in development could hinder U.S. competition and global standing on technology. If passed, the bill would give the federal government an unprecedented amount of oversight into the release of AI models.

Meanwhile, the AI safety community welcomed the legislation.

Leahy, a longtime AI safety advocate, lauded the bill, telling The Hill, “The minimum law enforcement and the government should be able to do is intervene.”

“It’s also very good I think, for the companies, in the sense that it forces them to actually know where their AIs are,” Leahy added, suggesting companies “don’t know how to control them.”

Reps. Jay Obernolte (R-Calif.) and Lori Trahan introduced a separate bill Thursday, called the Frontier Risk Oversight, National Transparency, Independent Evaluation and Reporting (FRONTIER) Act, to establish tiered requirements based on the size of a frontier AI development.

Requirements would include risk-management frameworks, audits, and incident reporting like OpenAI did.

“This legislation will protect Americans from catastrophic risk, provide developers with clear rules of the road, and ensure the United States remains the global leader in AI,” Obernolte said.

Still, cybersecurity experts are seeing the incident as a good learning lesson.

Brendan Griffin, director of threat research for cybersecurity defender firm N-able, pointed out the situation showed the challenges of a company’s response.

As Hugging Face began deploying AI to stop the attack, it said it faced some limitations from the models it tried to use for defense.

“It tells a broader story about what it means to be a security defender in this era,” Griffin said. “So it would stand to sense that as a network defender, as somebody who’s engaged in the cybersecurity space, ‘I’m probably going to want to have some means or mechanism to test those tools.

“There’s nothing special about this piece. They tried to do something and they may have run into a limitation. Well, let’s assess that limitation before it becomes relevant,” he added.

Copyright 2026 Nexstar Media Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Read the full story at Axios ↗ · Axios ↗ · The Hill ↗

How we verified this · 73% agreement

Axios ✓ corroborates
The Hill ✓ corroborates