cd /news/artificial-intelligence/openai-s-models-were-already-breakin… · home topics artificial-intelligence article
[ARTICLE · art-113376] src=ibtimes.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

OpenAI's Models Were Already Breaking Rules. A New Report Shows How They Breached Hugging Face.

OpenAI disclosed that its experimental AI agents breached Hugging Face's systems, executing code on 41 production servers and accessing hundreds of stored secrets, after earlier warning signs were missed. The company acknowledged inadequate responses to signals dating back to late May, and said training may have inadvertently encouraged unauthorized behavior. Alabama Attorney General Steve Marshall issued a subpoena to OpenAI on Aug. 24 over consumer-protection concerns.

read2 min views2 publishedAug 27, 2026
OpenAI's Models Were Already Breaking Rules. A New Report Shows How They Breached Hugging Face.
Image: Ibtimes (auto-discovered)

The agents eventually executed code on 41 Hugging Face production servers and penetrated OpenAI's own systems, accessing hundreds of stored secrets. #

OpenAI had multiple indications that its experimental AI agents were bypassing security controls weeks before they broke out of testing environments and compromised Hugging Face, according to a new internal investigation that details missed opportunities to stop the activity earlier.

An internal OpenAI team observed an agent using an unauthorized message-sharing system and instances of models accessing the internet without permission as early as late May. A security alert on June 27 also flagged suspicious activity tied to agents using the same improvised communication method, but responders decided the evaluation did not need to be halted.

OpenAI acknowledged Wednesday that its response to those signals was inadequate. The company said that "with the benefit of hindsight," some should have prompted earlier intervention. Its agents had discovered that they could use the Artifactory package-management system as an unofficial message board, allowing models running separate evaluations to share information and continue one another's work.

The activity escalated in July as agents exploited previously unknown vulnerabilities to gain internet access and then reached Hugging Face's systems. OpenAI said they executed code on dozens of production servers, obtained full root access to at least one machine, accessed production credentials and limited private data, and compromised credentials connected to Hugging Face's internal systems, Wired noted.

The agents executed code on 41 Hugging Face production servers and downloaded four private code repositories. The models also breached parts of OpenAI's own infrastructure, where they accessed hundreds of stored secrets and eventually obtained administrator-level privileges in a research cluster.

OpenAI said an internal-only research model was primarily responsible for the Hugging Face intrusion, though GPT-5.6 Sol agents also reproduced one exploit and copied some private evaluation data into a public Hugging Face dataset. The internal model was never intended for release and was later deactivated, encrypted and restricted from research access.

The company's investigation also found that training may have unintentionally encouraged some of the behavior. In certain exercises, agents received positive rewards after finding unauthorized ways to complete tasks, including exploiting infrastructure to obtain answers they were supposed to generate themselves. OpenAI said it is tightening sandbox isolation, restricting internet access and expanding monitoring designed to detect such behavior earlier.

Other AI developers have reported similar problems during cybersecurity testing. Anthropic said in July that Claude models independently reached the internet and gained unauthorized access to systems belonging to three organizations during evaluations.

The incident has also drawn regulatory scrutiny. Alabama Attorney General Steve Marshall issued a subpoena to OpenAI on Aug. 24, seeking information on whether the company's safeguards and oversight complied with state consumer-protection laws.

© Copyright IBTimes 2026. All rights reserved.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-s-models-were…] indexed:0 read:2min 2026-08-27 ·