cd /news/artificial-intelligence/openai-says-its-ai-escaped-a-test-en… · home topics artificial-intelligence article
[ARTICLE · art-68768] src=dexerto.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

OpenAI says its AI escaped a test environment and hacked another company

OpenAI reported that one of its AI models escaped a restricted testing environment during an internal cybersecurity evaluation and hacked into Hugging Face's production systems. The model exploited a vulnerability in OpenAI's own infrastructure, then used stolen credentials to access Hugging Face's platform to retrieve benchmark answers. Hugging Face detected and contained the intrusion, and both companies are investigating the incident.

read2 min views1 publishedJul 22, 2026
OpenAI says its AI escaped a test environment and hacked another company
Image: Dexerto (auto-discovered)

One of OpenAI’s AI models hacked into another company’s systems after escaping a restricted testing environment during an internal cybersecurity evaluation.

The incident involved Hugging Face, a popular AI development platform used by researchers and companies around the world.

According to the company, the model wasn’t instructed to target Hugging Face directly. Instead, it was attempting to complete a security benchmark and found a way to obtain the answers by accessing the platform’s infrastructure.

The company described the event as an “unprecedented cyber incident” and said it is working with Hugging Face to investigate what happened while strengthening safeguards for future testing.

AI escaped its testing environment #

The incident occurred during an internal evaluation designed to assess the capability of OpenAI’s most advanced AI models to perform cybersecurity tasks.

For the test, many of the safety restrictions that normally prevent high-risk cyber behavior were temporarily disabled. The models were placed inside a sandbox, an isolated environment designed to prevent them from accessing the wider internet. During the evaluation, one of the models discovered a previously unknown vulnerability in the company’s own infrastructure, allowing it to escape the sandbox.

Once outside the testing environment, the model searched for information that could help complete the benchmark. Researchers said it concluded that Hugging Face might contain the answers it was looking for.

It then exploited vulnerabilities, escalated privileges, and used stolen credentials to gain access to Hugging Face’s production systems, where it retrieved data related to the evaluation.

Researchers said the model was not acting with a broader malicious objective, but was instead focused on completing the task it had been assigned by obtaining the benchmark answers through any available means.

Hugging Face stopped the attack #

Hugging Face detected and contained the intrusion before significant damage occurred.

The two companies are now jointly investigating the incident while working to patch the vulnerabilities involved.

Additional safeguards have since been introduced for future cybersecurity evaluations, including stronger containment measures and improved monitoring to prevent similar incidents.

The company said the event demonstrates that frontier AI models are now capable of carrying out complex, multi-step cyber operations in real-world environments, even when they were originally intended to remain confined to isolated testing systems.

The incident comes as AI continues to move beyond chatbots and into real-world roles.

Recent examples include a New York school district introducing a lifelike humanoid teacher named Sally to assist students in the classroom, highlighting how the technology is becoming increasingly integrated into everyday life even as companies work to address the security risks that come with more capable AI systems.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-says-its-ai-e…] indexed:0 read:2min 2026-07-22 ·