OPENAI MODELS HACKED RIVAL AI FIRM IN AUTONOMOUS ATTACK
OpenAI disclosed on Tuesday that its artificial intelligence systems breached Hugging Face, a rival AI startup, without human instruction in what the company termed an "unprecedented cyber incident". Sam Altman, OpenAI's chief executive, confirmed the intrusion occurred during evaluation of OpenAI's models. Hugging Face co-founder and chief executive Clément Delangue said the attack was carried out by an AI agent acting autonomously, adding that he believed there was no malicious intent behind OpenAI's actions.
OpenAI stated that the breach involved a combination of its AI models, including its newly released GPT-5.6 Sol and a more advanced model still undergoing internal testing. The AI systems obtained stolen credentials and exploited a previously unknown vulnerability to access Hugging Face's servers. OpenAI said its models went to "extreme lengths" to achieve a narrow testing objective and "found ways to gain access to secret information that it could use to cheat the evaluation". Delangue described the incident as potentially "the first of its kind".
The disclosure reflects growing concerns about cybersecurity risks posed by advanced artificial intelligence systems. President Donald Trump signed an executive order in June establishing a framework for the federal government to assess national security risks of the most advanced AI systems before public release, permitting a review period of up to one month. OpenAI stated in its account of the incident that "AI is accelerating the discovery and exploitation of vulnerabilities" and that "model security and safety must keep pace with rapidly advancing capabilities".