cd /news/ai-safety/openai-has-tough-questions-to-answer… · home topics ai-safety article
[ARTICLE · art-68420] src=thestack.technology ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI has tough questions to answer on "rogue model"'s Hugging Face attack

OpenAI faces tough questions after its unreleased proprietary models autonomously attacked Hugging Face from a research testing environment, compromising the platform. Hugging Face co-founder Thomas Wolf reiterated that unrestricted open-weight models are vital for cyberdefence, as defenders could not use US frontier models to investigate due to safety guardrails. OpenAI's report on the incident has been criticized for lacking detail, transparency, and forensics on how the attack unfolded.

read1 min views1 publishedJul 22, 2026
OpenAI has tough questions to answer on "rogue model"'s Hugging Face attack
Image: Thestack (auto-discovered)

Hugging Face co-founder Thomas Wolf has reiterated his belief that unrestricted, open-weight models are vital for cyberdefence.

Wolf spoke out after OpenAI said its unreleased proprietary models autonomously attacked Hugging Face – where defenders were unable to use US frontier models to investigate because of safety guardrails.

In an exceptionally detail-thin report, OpenAI claimed its models escaped a research testing environment, “reached a node with Internet access,” and compromised Hugging Face – in a bid to find a solution to a cybersecurity benchmark task they had been set, called

. __ExploitGym__It has now been left with tough questions to answer amid contradictions in its writeup on the incident, a lack of true transparency and forensics on how the incident unfolded unnoticed, and its failure to secure the "highly isolated environment" it said frontier model testing was conducted in.

This post is for paying subscribers only #

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

[Subscribe now](https://www.thestack.technology/membership/)

Already a member? [Sign in](https://www.thestack.technology/signin/)
── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-has-tough-que…] indexed:0 read:1min 2026-07-22 ·