OpenAI did not detect an autonomous breach of another artificial intelligence (AI) company by one of its advanced AI models for a week and only after the FBI had been contacted by the hacked company, according to a report.
On Tuesday, OpenAI announced the AI company Hugging Face breach that occurred during one of OpenAI’s internal reviews of several of its models, including GPT-5.6 Groundcalling it an “unprecedented cyber incident.”
“The key lesson from this incident is that model safety and security must keep pace with rapidly evolving capabilities,” the company said. “We are strengthening the containment, surveillance, access control and evaluation practices used during model development.”
The Hugging Face hack began on July 11 and continued until July 13, Thomas Wolf, co-founder of Hugging Face, told Reuters.
TRUMP LAUNCHES GOLD EAGLE TO HUNTING CYBER DEFECTS WITH AI
OpenAI revealed Tuesday that one of its AI models had autonomously hacked another company’s infrastructure. (Omar Marques/SOPA Images/LightRocket via Getty Images, File/Getty Images)
It took several days before OpenAI realized its agent was behind the attack and the two companies only first communicated on July 20, four people, including Wolf, told the outlet.
OpenAI often runs simultaneous model tests, which can make it difficult for employees to monitor everything, four people told Reuters.
Hugging Face told Reuters it was preparing a public timeline of the hack.
According to OpenAI, the incident took place during an internal assessment designed to measure the advanced cyber capabilities of its AI models. The researchers disabled some built-in security measures and ran the models in an isolated test environment with limited internet access.
OpenAI said the models exploited an unknown software flaw to gain access to the internet and then breached Hugging Face’s systems in an apparent attempt to find answers to a cybersecurity benchmark.
OPENAI’S SAM ALTMAN WANTS TO NEGOTIATE A 5% SHARING IN THE COMPANY FOR US IF COMPETITORS AGREE TO A KEY PROVISION
Hugging Face said it was preparing a timeline of the hack. (Jakub Porzycki/NurPhoto via Getty Images, File/Getty Images)
OpenAI said it was now implementing tighter security controls while vulnerabilities were patched and strengthening protections around future AI education and training. evaluations.
It wasn’t until July 16, after Hugging Face wrote in a blog post that it had been hacked by an “autonomous AI agent system,” that OpenAI realized one of its agents was the source, two people told Reuters.
This was a week after the responsible agent first attempted to exit its OpenAI test environment.
And by the time OpenAI contacted Hugging Face about the attack, they had already contacted the FBI.
OpenAI told Reuters there were several inaccuracies in its reporting, but did not respond when asked for specifications.
OpenAI CEO Sam Altman publicly announced the attack on Tuesday. (Sean Gallup/Getty Images, FIchier/Getty Images)
OpenAI shared this statement with FOX Business: “We recognize that there are many questions and speculative details circulating regarding the Hugging Face incident. This is an unprecedented incident and we believe it marks an important moment for AI security.
“We always conduct a thorough review with external advisors and under the supervision of our safety and security committee. Once the review is complete, we plan to release a technical report on our learnings in the coming weeks.
The FBI told FOX Business it declined to comment.
FOX Business also reached out to Hugging Face.
In an X article this week, Hugging Face co-founder and CEO Clem Delangue addressed the incident after OpenAI CEO Sam Altman announced the hack.
OpenAI said one of its AI models compromised another company’s systems during internal testing, prompting a joint investigation with AI startup Hugging Face. (Reuters/Dado Ruvic, archives / Reuters)
“We suspected that last week’s cyberattack might have come from a border lab, given the sophistication of the agent. It turns out that’s the case!” Delangue wrote.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
“We’ve spent the last 24 hours working closely with the @OpenAI team (thank you!), and we’re confident there was no malicious intent on their part. It’s pretty mind-blowing that this all happened autonomously! The investigation is ongoing and we’ll share more learnings on what may be the first incident of its kind!”
Michael Sinkewicz of FOX Business contributed to this report.




























