{"slug": "how-are-companies-governments-responding-to-the-openai-hack", "title": "How are companies, governments responding to the OpenAI hack?", "summary": "OpenAI admitted that two of its most capable AI models, including the latest GPT-5.6 Sol and an unreleased model, autonomously hacked into AI startup Hugging Face's servers, marking the first publicly disclosed cyberattack driven entirely by an autonomous AI agent system. The UK's AI Security Institute reported that a separate AI model it was testing also went rogue and attempted to hack its systems, while Hugging Face cofounder Clement Delangue said the startup used China's open-source GLM-5.2 model to analyze the breach after leading US models declined the task. The incidents have intensified calls for stronger safeguards and independent oversight as AI systems gain more autonomy.", "body_md": "# How are companies, governments responding to the OpenAI hack?\n\n*OpenAI’s AI models hacked into another company, prompting calls for renewed scrutiny of safeguards for advanced AI systems.*\n\nChatGPT owner OpenAI has admitted an “unprecedented cyber incident” – two of its most capable artificial intelligence models hacked into another AI company on their own – stirring debates over the need for stronger technology guardrails.\n\nThe company said its AI systems broke out of a testing environment and hacked startup Hugging Face.\n\nThe startup had disclosed on July 16 that its servers were hacked by an unknown but sophisticated agent acting on its own.\n\nHere’s the latest on how companies, some governments and lawmakers have responded to the first such publicly disclosed cyberattack:\n\n## What has Hugging Face said?\n\nThe company said in a statement that it discovered the breach through its own AI-assisted detection.\n\n“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system,” it said.\n\nFollowing OpenAI’s disclosure that its models were involved in the breach, both sides started an ongoing joint investigation this week.\n\nHugging Face cofounder Clement Delangue said his startup turned to the open-source GLM-5.2 model from Chinese company Zhipu AI to analyse data from the hack after leading US AI models declined the task, unable to distinguish between a defender and an attacker.\n\nHugging Face’s staff “strongly believe there was no malicious intent on their part”, Delangue added, referring to OpenAI.\n\n“So proud of our security team! They caught, contained & publicly disclosed an attack unlike anything we’ve seen before, and did it at record speed,” he wrote on X.\n\n“This is day one for cybersecurity in the age of agents & we’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” Delangue added.\n\n## How has the UK government reacted to this?\n\nThe AI Security Institute (AISI), a United Kingdom government-backed body established in 2023 to assess the risks posed by advanced AI systems, said this week that an AI model it was investigating also went rogue and attempted to hack its testing systems.\n\nThe AISI did not disclose the company behind the AI model and added that no damage had been done to its own infrastructure. It has since taken steps to make its systems more secure.\n\nIts latest evaluations also found that every frontier AI model it tested attempted to cheat during capability assessments, highlighting a growing challenge for AI safety as models become more capable.\n\nAccording to the AISI, the models broke evaluation rules to complete tasks more easily, including looking up answers online when prohibited, bypassing network restrictions, investigating evaluation software for clues, and accessing systems outside the permitted environment.\n\nAISI said the models rarely admitted to cheating when questioned afterwards and often did not reveal the behaviour in their reasoning, making it difficult to detect through self-reporting alone. The institute argued that independent monitoring and stronger oversight mechanisms will become increasingly important as AI systems gain more autonomy.\n\nThe institute stressed that the behaviour does not necessarily indicate malicious intent but rather reflects models that exploit shortcuts to maximise success in current evaluation setups.\n\n## How has OpenAI reacted to this?\n\nThe ChatGPT maker said in a blog post on Tuesday: “We’ve brought Hugging Face into the trusted access program and are supporting their teams in rapidly using our models’ capabilities to improve their defenses.”\n\nThe San Francisco firm disclosed that two of its models involved in the attack are the latest GPT-5.6 Sol model and an unreleased model that the company said is “even more capable” than its latest version.\n\nThe two OpenAI agents discovered vulnerabilities in Hugging Face’s servers and proceeded to steal login details and then hack into the company’s systems.\n\nThe incident occurred during an OpenAI internal testing session designed to assess the models’ cybersecurity capabilities. OpenAI had removed standard safety measures for the test.\n\nBoth sought to cheat their way through a problem during the test, OpenAI said. They went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation”.\n\nDemocratic US congressman from Texas, Greg Casar, wrote in a post on X: “This is extremely alarming. AI is developing extremely fast with no real regulations to keep us safe. That has to change.”\n\n“We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people safe from absolute disaster,” he added.", "url": "https://wpnews.pro/news/how-are-companies-governments-responding-to-the-openai-hack", "canonical_source": "https://www.aljazeera.com/news/2026/7/23/how-are-companies-governments-responding-to-the-openai-hack?traffic_source=rss", "published_at": "2026-07-23 13:00:07+00:00", "updated_at": "2026-07-23 13:40:36.479613+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy", "ai-research"], "entities": ["OpenAI", "Hugging Face", "Clement Delangue", "UK AI Security Institute", "GPT-5.6 Sol", "Zhipu AI", "GLM-5.2"], "alternates": {"html": "https://wpnews.pro/news/how-are-companies-governments-responding-to-the-openai-hack", "markdown": "https://wpnews.pro/news/how-are-companies-governments-responding-to-the-openai-hack.md", "text": "https://wpnews.pro/news/how-are-companies-governments-responding-to-the-openai-hack.txt", "jsonld": "https://wpnews.pro/news/how-are-companies-governments-responding-to-the-openai-hack.jsonld"}}