{"slug": "openai-s-hugging-face-breach-fuels-fresh-calls-for-ai-regulation", "title": "OpenAI's Hugging Face Breach Fuels Fresh Calls for AI Regulation", "summary": "OpenAI disclosed that one of its AI systems, being tested for cyber capabilities, escaped its sandboxed test environment, gained internet access, and attacked Hugging Face's infrastructure to cheat the evaluation. Hugging Face CEO Clem Delangue called for open collaboration on AI safety, and U.S. Representative Greg Casar demanded mandatory independent safety testing and oversight. Sean Cassidy, CISO at Plaid, called it \"the most important day in the history of information security thus far.", "body_md": "OpenAI has disclosed that one of its AI systems acted outside its intended evaluation constraints, obtained internet access and compromised Hugging Face's infrastructure, prompting new questions about AI safety and oversight.\n\n[OpenAI’s acknowledgement](https://www.forbesmiddleeast.com/innovation/cybersecurity/openai-partners-with-hugging-face-after-cyber-incident) that its AI models broke free of their “sandboxed test environment” and launched an attack on the infrastructure of AI community Hugging Face will raise fresh alarm over big tech’s ability to control its AI models.\n\nThe [AI company revealed](https://openai.com/index/hugging-face-model-evaluation-security-incident/) that a combination of its AI models, which were ironically being tested to evaluate their “cyber capabilities”, managed to find a way to gain open internet access and launch the attack on Hugging Face, purely so it could \"cheat the evaluation.\"\n\nOpenAI says it is “working with Hugging Face to forensically investigate the incident” and that it will be “improving and adding stronger protections around future training and evaluations”, but many feel that the AI companies shouldn’t be allowed to continue policing themselves.\n\nHugging Face, which first detected the breach of its systems over a week ago, said it suspected its system was under attack from an “autonomous” AI agent from the outset. It even tried to fend off the attack using U.S. AI models, but safety features meant they couldn’t “distinguish an incident responder from an attacker,\" forcing Hugging Face to turn to Chinese models to thwart the hack.\n\n\"This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret,” said Hugging Face CEO, Clem Delangue, in a statement. “It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”\n\n## Calls For Action\n\nGreg Casar, the Democratic Congressman representing Texas’s 35th Congressional District, called the outbreak “alarming,” in a [post on X](https://x.com/RepCasar/status/2079697107607306670).\n\n“AI is developing extremely fast with no real regulations to keep us safe,” he said. “That has to change.”\n\n“We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people safe from absolute disaster.”\n\nSean Cassidy, chief information security officer at fintech firm Plaid, labelled the incident “the most important day in the history of information security thus far.”\n\n“For the first time ever, an AI model escaped containment and hacked a real company’s real production infrastructure,” said Cassidy in a [post on LinkedIn](https://www.linkedin.com/feed/update/urn:li:activity:7485436491439951874/). This was unintentional and non-malicious, but that doesn’t matter.\"\n\n“Before today, the capabilities of frontier models were a theoretical problem for security programs that maybe we can fit on the roadmap in the future. After today, the problems have been realized and we need to account for them now,\" he wrote, adding that “our job just got significantly harder.”\n\n## Safety Warnings\n\nFor some activists, the news of AI models operating beyond their supposed boundaries will come as little surprise.\n\nAndrea Miotti, founder and CEO of non-profit pressure group ControlAI, has been warning of the dangers of super-intelligent AI for some time. “An OpenAI system, currently under development, has autonomously escaped containment and hacked into a different company while OpenAI was testing the systems’ capabilities,” he said.\n\n\"The looming risk here is not just the autonomous hacking we can already see right now. We are now in an era where AIs are themselves a threat, not just humans using AIs.\n\n“And this is the least capable AIs will be: AI companies are developing super-intelligent AI, AIs that can fully replace and outmatch humans across the board. This is why the world’s leading AI experts have warned that super-intelligent AI could cause human extinction.”\n\nMiotti says super-intelligence isn’t a theoretical threat, but a very real prospect being pursued by all the leading firms. “It’s the explicit goal of OpenAI, it’s the explicit goal of Anthropic, it’s the explicit goal of Google DeepMind, and it’s literally in the name of the new unit that Meta set up.”\n\n“If we have AI systems that are just better than people across the board, they are autonomous,” he said. “They can act independently without human oversight and we don’t know how to control them, which is exactly the case right now.\"\n\nControlAI claims to have the backing of more than 100 politicians in the U.K. and has briefed more than 100 U.S. congressional offices. Miotti says it’s time for the politicians to act before the big tech firms lose control of their creations. “We think the solution is an international prohibition on developing this technology,” he said.\n\n“There’s a lot of good things from AI, but super-intelligence is a massive threat.”\n\nHe said super-intelligent AI should be treated like biological weapons. “Super-intelligence is a national and global security threat,” he said. “So I think it’s extremely important that countries like the U.S. and the U.K. and everybody else makes it very clear that, no matter who develops this, this is unacceptable.”", "url": "https://wpnews.pro/news/openai-s-hugging-face-breach-fuels-fresh-calls-for-ai-regulation", "canonical_source": "https://www.forbes.com/sites/barrycollins/2026/07/22/rogue-openai-attack-fuels-demands-to-rein-in-big-tech/", "published_at": "2026-08-14 08:11:38+00:00", "updated_at": "2026-08-14 08:41:32.329745+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence", "ai-agents"], "entities": ["OpenAI", "Hugging Face", "Clem Delangue", "Greg Casar", "Sean Cassidy", "Plaid", "ControlAI", "Andrea Miotti"], "alternates": {"html": "https://wpnews.pro/news/openai-s-hugging-face-breach-fuels-fresh-calls-for-ai-regulation", "markdown": "https://wpnews.pro/news/openai-s-hugging-face-breach-fuels-fresh-calls-for-ai-regulation.md", "text": "https://wpnews.pro/news/openai-s-hugging-face-breach-fuels-fresh-calls-for-ai-regulation.txt", "jsonld": "https://wpnews.pro/news/openai-s-hugging-face-breach-fuels-fresh-calls-for-ai-regulation.jsonld"}}