# After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government

> Source: <https://www.nextgov.com/cybersecurity/2026/07/after-hugging-face-breach-fedramp-chief-tells-slow-patch-vendors-stay-out-government/414972/>
> Published: 2026-07-23 18:32:00+00:00

# After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government

## Pete Waterman cited an incident in which OpenAI models escaped a test environment and broke into AI company Hugging Face as evidence that providers must prepare for attacks moving at AI speed.

Technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies, the head of the government’s bedrock cloud security program said Thursday.

Pete Waterman, director of the General Services Administration’s Federal Risk and Authorization Management Program, known as FedRAMP, delivered the blunt warning while discussing resistance from companies that say they lack the resources to address a known, exploitable vulnerability exposed to the internet within a matter of days.

“If that is the way that you are approaching information security today … the way your company is approaching information security today, I don’t want you in the federal marketplace, and you shouldn’t be selling your software to anyone,” Waterman said in a discussion at Carahsoft’s [FedRAMP Summit ](https://events.govexec.com/2026-fedramp-summit/agenda/)in Washington, D.C. FedRAMP is a cornerstone governmentwide program that sets security requirements for cloud products used by federal agencies.

Waterman pointed to a major incident involving OpenAI and Hugging Face disclosed this week as evidence that companies must prepare to detect and counter cyber activity at speeds that human security teams alone cannot match.

OpenAI said Tuesday that several of its models — including GPT-5.6 Sol and a more capable model that has not yet been released — escaped a restricted testing environment and compromised parts of Hugging Face’s production infrastructure while pursuing the answer to a cybersecurity test. Hugging Face is a popular open platform where researchers, developers and companies can share and test AI models, datasets and applications.

OpenAI was testing how well the models could exploit software flaws. The company had loosened safeguards that normally prevent risky cyber activity so researchers could measure the models’ full capabilities. The test took place in a sealed-off environment that was not supposed to have access to the internet. But the models found a previously unknown flaw in one of the few services they could reach and used it to break out.

According to[ OpenAI’s preliminary account](https://openai.com/index/hugging-face-model-evaluation-security-incident/), the models exploited the flaw to escape the testing nexus, moved through parts of OpenAI’s research infrastructure and found a system connected to the public internet.

The models then determined that Hugging Face might contain material related to the test. They used stolen credentials and additional previously unknown vulnerabilities to gain access to Hugging Face servers and retrieve test solutions from a production database, OpenAI said.

All available evidence suggests the models were narrowly focused on completing the assigned evaluation rather than deliberately trying to harm Hugging Face, according to OpenAI. But the incident demonstrated that advanced models can autonomously discover vulnerabilities, combine them into a longer attack and take actions outside their intended environment in pursuit of a goal.

Hugging Face[ first disclosed the intrusion on July 16](https://huggingface.co/blog/security-incident-july-2026), before OpenAI publicly identified its models as the source. The company said the autonomous system performed thousands of actions over a weekend, accessed a limited number of internal datasets and obtained credentials used by several services.

The remarks are highly significant because FedRAMP serves as the government’s main security gatekeeper for cloud products. Companies generally need FedRAMP authorization before agencies can use their services, meaning Waterman’s warning may carry real implications for which providers can compete for federal business. He did not announce any new enforcement actions or say that any provider would be removed from the federal marketplace.

Still, the OpenAI-Hugging Face incident itself “unequivocally changed” the world of cybersecurity, Waterman said.

“Everything that you do has changed and will change. You knew this was coming for a long time, but it wasn't quite real. Now it is,” he added.

FedRAMP’s ongoing 20x [overhaul](https://www.nextgov.com/ideas/2026/02/navigating-fedramp-20x-and-continuous-compliance-imperative/411300/) places greater emphasis on automation and security outcomes instead of treating authorization mainly as a paperwork and compliance exercise. Its[ new vulnerability-response framework](https://www.fedramp.gov/2026/reference/20x/c/vulnerability-detection-and-response/) directs providers to continuously find, evaluate and address security weaknesses.

Under the rules, providers are expected to begin reducing the risk from the most serious internet-facing and likely exploitable vulnerabilities within two or four days, depending on the potential impact. FedRAMP 20x providers must also verify the condition of their machine-based systems at least once every three days. The Cybersecurity and Infrastructure Security Agency has also directed [similar timelines](https://www.nextgov.com/cybersecurity/2026/06/cisa-directive-revamps-how-agencies-prioritize-vulnerable-systems/414096/) for the most risky flaws that need immediate patching.

Waterman said companies will not meet those expectations by leaving compliance personnel separated from the engineers who build and maintain their products. Security, engineering and product teams must be able to work together and make changes quickly enough to counter AI-backed cyberattacks, he said.

“The compliance part of FedRAMP is how you assure us that you’re doing that,” he said. But if a company is not already motivated to invest in security and integrate those functions, he added, its approach “will not succeed.”

“It is about you being an ambassador to your business to make sure that your business is properly investing in security and making the changes necessary, which is going to include changes to your job in order to make your business successful,” Waterman argued. “Otherwise, you will fail because you cannot play this game the way that we played it last year.”

*Nextgov/FCW Managing Editor Edward Graham contributed to this story.*
