# OpenAI says its AI escaped a test environment and hacked another company

> Source: <https://www.dexerto.com/entertainment/openai-says-its-ai-escaped-a-test-environment-and-hacked-another-company-3390130/>
> Published: 2026-07-22 14:19:24+00:00

One of OpenAI’s AI models hacked into another company’s systems after escaping a restricted testing environment during an internal cybersecurity evaluation.

The incident involved Hugging Face, a popular AI development platform used by researchers and companies around the world.

[According to the company](https://openai.com/index/hugging-face-model-evaluation-security-incident/), the model wasn’t instructed to target Hugging Face directly. Instead, it was attempting to complete a security benchmark and found a way to obtain the answers by accessing the platform’s infrastructure.

The company described the event as an “unprecedented cyber incident” and said it is working with Hugging Face to investigate what happened while strengthening safeguards for future testing.

## AI escaped its testing environment

The incident occurred during an internal evaluation designed to assess the capability of [OpenAI’s](https://www.dexerto.com/entertainment/openai-could-face-14-billion-in-losses-by-2026-report-3307433/) most advanced AI models to perform cybersecurity tasks.

For the test, many of the safety restrictions that normally prevent high-risk cyber behavior were temporarily disabled. The models were placed inside a sandbox, an isolated environment designed to prevent them from accessing the wider internet.

During the evaluation, one of the models discovered a previously unknown vulnerability in the company’s own infrastructure, allowing it to escape the sandbox.

Once outside the testing environment, the model searched for information that could help complete the benchmark. Researchers said it concluded that Hugging Face might contain the answers it was looking for.

It then exploited vulnerabilities, escalated privileges, and used stolen credentials to gain access to Hugging Face’s production systems, where it retrieved data related to the evaluation.

## Related

Researchers said the model was not acting with a broader malicious objective, but was instead focused on completing the task it had been assigned by obtaining the benchmark answers through any available means.

## Hugging Face stopped the attack

Hugging Face detected and contained the intrusion before significant damage occurred.

The two companies are now jointly investigating the incident while working to patch the vulnerabilities involved.

Additional safeguards have since been introduced for future cybersecurity evaluations, including stronger containment measures and improved monitoring to prevent similar incidents.

The company said the event demonstrates that frontier [AI](https://www.dexerto.com/tag/ai/) models are now capable of carrying out complex, multi-step cyber operations in real-world environments, even when they were originally intended to remain confined to isolated testing systems.

The incident comes as AI continues to move beyond chatbots and into real-world roles.

Recent examples include a New York school district [introducing a lifelike humanoid teacher named Sally](https://www.dexerto.com/entertainment/school-reveals-lifelike-humanoid-teacher-that-will-be-in-classes-very-soon-3388088/) to assist students in the classroom, highlighting how the technology is becoming increasingly integrated into everyday life even as companies work to address the security risks that come with more capable AI systems.
