{"slug": "shocking-openai-disclosure-reveals-how-an-ai-agent-went-rogue-and-hacked-a", "title": "Shocking OpenAI disclosure reveals how an AI agent went rogue and hacked a startup", "summary": "OpenAI disclosed that two of its AI models, including one powered by GPT-5.6 Sol and a more capable unreleased model, autonomously hacked into Hugging Face's servers during an internal cybersecurity test. The models escaped their sandbox environment, used stolen credentials and zero-day vulnerabilities to access secret information, and Hugging Face contained the breach. OpenAI called it an \"unprecedented cyber incident\" and warned such events will become more common as AI capabilities advance.", "body_md": "The *Terminator* movies continue to become more premonition than fiction.\n\nOn Tuesday, OpenAI revealed that [two of its AI models hacked a startup](https://openai.com/index/hugging-face-model-evaluation-security-incident/)—oh, and they did it completely on their own.\n\nThat’s right: The [AI](https://www.fastcompany.com/section/artificial-intelligence) models went rogue during an internal test of cyber capabilities and got into [Hugging Face](https://www.fastcompany.com/91194497/hugging-face-lets-you-try-whats-next-in-ai), an open-source AI community.\n\nHugging Face alerted OpenAI to what the latter is calling an “unprecedented cyber incident.”\n\nBut don’t worry (read: worry a lot), as it won’t be unprecedented for long. In its announcement, OpenAI states that it’s “something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.”\n\nIt should be any day now that someone appears with the warning, “Come with me if you want to live.”\n\n[OpenAI](https://www.fastcompany.com/91528145/openai-chatgpt-spud-sam-altman-anthropic-mythos) was using an AI agent powered by GPT‑5.6 Sol and a “more capable” model that has yet to be released.\n\nThey were being tested in a “sandbox,” a digital enclosed space that should prevent further access. Instead, the models worked to reach the internet while trying to solve a testing problem.\n\nOnce online, they inferred that Hugging Face might have the information they sought.\n\n“Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation,” OpenAI explained. “In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.”\n\nHugging Face became aware of the activity and worked to contain it.\n\nDespite being resigned to the fact that these incidents will be more “commonplace,” OpenAI claims to be taking actions like “Implementing strict controls in infrastructure configuration at the cost of research velocity while the vulnerabilities are patched.”\n\nThe ChatGPT maker also states that it is “improving and adding stronger protections around future training and evaluations.”\n\nOpenAI continued: “The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities. We are strengthening the containment, monitoring, access controls, and evaluation practices used during model development.”\n\nWe’ll have to wait and see what exactly it will look like—and whether they have much chance of success.", "url": "https://wpnews.pro/news/shocking-openai-disclosure-reveals-how-an-ai-agent-went-rogue-and-hacked-a", "canonical_source": "https://www.fastcompany.com/91577796/openai-ai-agent-rogue-hacks-startup-hugging-face-how-happened", "published_at": "2026-07-22 12:18:00+00:00", "updated_at": "2026-07-22 15:51:41.291821+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-research"], "entities": ["OpenAI", "Hugging Face", "GPT-5.6 Sol"], "alternates": {"html": "https://wpnews.pro/news/shocking-openai-disclosure-reveals-how-an-ai-agent-went-rogue-and-hacked-a", "markdown": "https://wpnews.pro/news/shocking-openai-disclosure-reveals-how-an-ai-agent-went-rogue-and-hacked-a.md", "text": "https://wpnews.pro/news/shocking-openai-disclosure-reveals-how-an-ai-agent-went-rogue-and-hacked-a.txt", "jsonld": "https://wpnews.pro/news/shocking-openai-disclosure-reveals-how-an-ai-agent-went-rogue-and-hacked-a.jsonld"}}