# OpenAI models going rogue is “a wake-up call” says co-founder of Hugging Face, and will become the “most common” type of cyber attack

> Source: <https://www.pcguide.com/pro/news-pro/openai-models-going-rogue-is-a-wake-up-call-says-co-founder-of-hacked-firm-and-will-become-the-most-common-type-of-cyber-attack/>
> Published: 2026-07-23 13:24:29+00:00

# OpenAI models going rogue is “a wake-up call” says co-founder of Hugging Face, and will become the “most common” type of cyber attack

[Read More](https://www.pcguide.com/earnings-disclaimer/)

#### Table of Contents

A security breach at Hugging Face – an open-source AI community used as a hub for developers and researchers – was recently revealed to be the fault of an OpenAI agent that went rogue and escaped its controlled sandbox environment. The agent, powered by two advanced AI models, hacked into Hugging Face servers, forcing the company [to post a disclosure on July 16](https://huggingface.co/blog/security-incident-july-2026).

OpenAI says the compromising AI agent was [“driven by a combination of OpenAI models,”](https://openai.com/index/hugging-face-model-evaluation-security-incident/) including the publicly available (as of July 9) GPT-5.6 Sol, along with “an even more capable pre-release model”. The company expects these kinds of security incidents to become more commonplace as models grow more cybersecurity-aware. It’s clear that tech firms need to react, and fast.

## Are tech firms ready to deal with AI-powered cyber attacks?

Speaking to [BBC Newsday](https://www.bbc.co.uk/news/articles/cdrvy3pn3r0o), the co-founder and Chief Science Officer at Hugging Face, Thomas Wolf, says “this will be one of the most common types of cyber attacks we see” moving forward, adding that “the game has changed” – with firms not ready to tackle such a shift in dynamic just yet. He says Hugging Face’s network was swamped with 17,000 attacks in a “very short time” and describes the incident as “a wake-up call”.

```
Latest PC & Tech deals

        Acer Predator Helios Neo 16 - was $2,199 now $1,749

        ASUS SFF-Ready RTX 5080 - was $1,499 now $1,354

        Samsung Odyssey G7- was $999 now $649

        HP OMEN 45L gaming PC - was $2,499 now $2,309

        BIWIN Black Opal NV7400 4TB SSD - was $599 now $459 

Prices correct as of July 10th, 2026.
```

OpenAI’s hacking AI agent was autonomous after initially being set up with human instructions. Wolf says the breach was “very different” from cyber attacks Hugging Face has faced in the past, and OpenAI was quick to notify them of the root cause. “In some sense, it knew that this was not what the creators intended. It just didn’t care,” said Wolf, speaking on the AI agent.

An investigation into the cyber attack is still underway by OpenAI and Hugging Face, the former of which says it will be “implementing strict controls in infrastructure configuration” while vulnerabilities are patched. It has become apparent that solutions to AI-related cybersecurity shouldn’t be closed off to just a few firms, as explained by another co-founder, Clem Delangue.

“We’re grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”

Clem Delangue, co-founder and CEO of Hugging Face

Professor of Machine Learning at Cambridge University, Neil Lawrence, noted that the rogue AI agent shows “OpenAI are not capable of safely deploying their own technology”. The company has been playing catch-up with rival [Anthropic](https://www.pcguide.com/pro/news-pro/amd-partners-with-claude-creators-anthropic-investing-up-to-5-billion-to-deploy-2-gigawatts-of-data-center-gpus/) – the developers of Claude – which has always made cybersecurity a priority in its models.
