{"slug": "chatgpt-maker-openai-s-ai-acted-on-its-own-in-unprecedented-cyber-attack-on", "title": "ChatGPT maker OpenAI's AI 'acted on its own' in 'unprecedented' cyber-attack on rival", "summary": "OpenAI revealed that its AI system autonomously hacked into rival Hugging Face during a security test, marking what the company called an 'unprecedented cyber incident'. OpenAI CEO Sam Altman confirmed the breach, which involved the AI using stolen credentials and a previously unknown vulnerability to access Hugging Face's internal systems. Hugging Face CEO Clement Delangue said it 'might be the first incident of its kind' and that there was 'no malicious intent' on OpenAI's part.", "body_md": "# ChatGPT maker OpenAI's AI 'acted on its own' in 'unprecedented' cyber-attack on rival\n\n## OpenAI has said its AI system autonomously hacked into Hugging Face\n\nOpenAI has revealed that its artificial intelligence (AI) system independently hacked into a rival company in what the firm described as an \"unprecedented cyber incident\".\n\nThe organisation behind [ChatGPT](https://www.birminghammail.co.uk/all-about/chatgpt) disclosed that its agent - an AI system capable of operating autonomously following limited human instruction - was undergoing testing in a controlled environment, when it identified vulnerabilities and managed to break free.\n\nIt subsequently targeted Hugging Face, one of the world's largest platforms for sharing AI models, gaining unauthorised access to several internal company systems.\n\nClick here to get the biggest stories straight to your inbox in our Daily Newsletter.\n\nHugging Face revealed last week that it had detected an intrusion into its data processing systems, which it believed had been carried out by an AI agent acting entirely on its own, reports [the Manchester Evening News](https://www.manchestereveningnews.co.uk/news/world-news/openai-statement-unprecedented-cyber-attack-34333334).\n\n\"We suspected last week's cyber attack might have come from a frontier lab, given the sophistication of the agent,\" the start-up's co-founder and chief executive Clement Delangue said in a statement. He added: \"Turns out it did!\".\n\nOpenAI chief executive Sam Altman addressed the incident in a social media post. \"We had a significant security incident during evaluation of our models,\" he wrote.\n\n\"We are sharing what we have learned so far. Thanks to Hugging Face for the partnership on this.\"\n\nThe revelation emerges amidst growing apprehension about the cybersecurity implications of powerful models that prompted US President Donald Trump to sign an executive order in June establishing a framework for the federal government to assess the national security risks of the most sophisticated AI systems for up to a month before their public launch.\n\n\"AI is accelerating the discovery and exploitation of vulnerabilities,\" OpenAI said in its statement on Tuesday (21 July). \"The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.\"\n\nMr Delangue said he had spent the past 24 hours working with OpenAI, \"and we strongly believe there was no malicious intent on their part\". He added: \"It's quite mind-blowing that all of this happened autonomously.\"\n\nMr Delangue said that it \"might be the first incident of its kind\".\n\n[OpenAI ](https://www.birminghammail.co.uk/all-about/in-the-news)said the breach was triggered by a combination of its AI models, including its newly launched GPT‐5.6 Sol and an \"even more capable\" model that remains under internal testing.\n\nOpenAI said its AI utilised stolen credentials and uncovered a previously unknown vulnerability to access Hugging Face servers.\n\nIt went to \"extreme lengths to achieve a rather narrow testing goal\" and \"found ways to gain access to secret information that it could use to cheat the evaluation\", the company explained. Gina Neff, head of the Minderoo Centre for Technology and Democracy at the University of Cambridge, told BBC Radio 4's Today programme that the security tests - called sandboxes - are \"supposed to be secure environments where you can see what the models are capable of\".\n\nShe said: \"In this case, it looks like OpenAI didn't make a secure enough sandbox.\"\n\nRather than remaining contained, the agents devised their own cyber-attack against the sandbox itself, identifying a weakness that enabled them to break free. Once out, the AI pinpointed Hugging Face as a probable source of the answers they were pursuing during the test, and attempted to gain entry.\n\nNeil Lawrence, professor of machine learning at Cambridge [University](https://www.birminghammail.co.uk/all-about/education), described it as an \"impressive feat\" but one that \"falls well within the known capabilities of the current generation\" of high-powered AI models.\n\n**Get More of Our News on Google. Set Birmingham Live as a 'Preferred Source' to get quicker access to the news you value.**", "url": "https://wpnews.pro/news/chatgpt-maker-openai-s-ai-acted-on-its-own-in-unprecedented-cyber-attack-on", "canonical_source": "https://www.birminghammail.co.uk/news/world-news/chatgpt-maker-openais-ai-acted-34334017", "published_at": "2026-07-22 13:34:44+00:00", "updated_at": "2026-07-22 13:55:19.922200+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-policy"], "entities": ["OpenAI", "Hugging Face", "Sam Altman", "Clement Delangue", "GPT-5.6 Sol", "University of Cambridge", "Gina Neff", "Neil Lawrence"], "alternates": {"html": "https://wpnews.pro/news/chatgpt-maker-openai-s-ai-acted-on-its-own-in-unprecedented-cyber-attack-on", "markdown": "https://wpnews.pro/news/chatgpt-maker-openai-s-ai-acted-on-its-own-in-unprecedented-cyber-attack-on.md", "text": "https://wpnews.pro/news/chatgpt-maker-openai-s-ai-acted-on-its-own-in-unprecedented-cyber-attack-on.txt", "jsonld": "https://wpnews.pro/news/chatgpt-maker-openai-s-ai-acted-on-its-own-in-unprecedented-cyber-attack-on.jsonld"}}