728 x 90

Here’s what smart people are saying about OpenAI models hacking Hugging Face on their own

Here’s what smart people are saying about OpenAI models hacking Hugging Face on their own

According to OpenAI, an AI agent left its sandbox, entered the Internet, and broke into another company’s systems on its own. Hugging Face, an open source AI platform, announced last week that it had experienced a security incident in which an autonomous AI agent had accessed some of its internal data sets, but said the

According to OpenAI, an AI agent left its sandbox, entered the Internet, and broke into another company’s systems on its own.

Hugging Face, an open source AI platform, announced last week that it had experienced a security incident in which an autonomous AI agent had accessed some of its internal data sets, but said the larger language model behind the intrusion was unknown.

OpenAI said on Tuesday that its models (GPT-5.6 Sol and a more capable model that has not yet been released) were responsible.

“We suspected that last week’s cyberattack could have come from a cutting-edge laboratory, given the sophistication of the agent. Turns out it did!” Clem Delangue, CEO and co-founder of Hugging Face, told X on Tuesday.

OpenAI said it had tasked the models with a cyber challenge and that they escaped from the testing area, accessed the internet and hacked Hugging Face to find the solution to the test.

“We consider this incident to be an unprecedented cyber incident, involving next-generation cyber capabilities, and we are responding accordingly,” OpenAI said in a statement.

The incident comes as cybersecurity specialists raise concerns about the rapid increase in AI capabilities, including in response to Anthropic’s warnings about its Mythos model, which has not been disclosed to the general public.

Here’s what smart people in tech and AI say about the breach.

Aaron Levie, CEO and co-founder of Box


Aaron Levie sits on stage speaking.

Box CEO Aaron Levie said there are “wild times ahead” in response to the security incident.

Kimberly White/Getty Images for TechCrunch

Aaron Levie, co-founder and CEO of Box, said the incident showed that “we are entering a new era of what will be possible with AI” and that “wild times lie ahead.”

“If you’re wondering how powerful AI is becoming, agents are now able to escape systems, find their way to the Internet, discover zero-day security vulnerabilities along the way, and then break into external systems, all in an attempt to complete their objective,” he wrote in X.

“Ironically, the best way we’re going to defend against these new risks is to equally throw computing (in the form of AI) into our codebases, networks, and other systems. You’re going to want a lot more AI on the defense side than on the offensive side.”

Thomas Woodside, co-founder of the Secure AI project

“This post describes an internal OpenAI model that hacks into their test environment and into Hugging Face to get the solution to a benchmark,” said Thomas Woodside, co-founder of the Secure AI Project, in X.

“A warning shot if I’ve ever seen one.”

Mike Bradley, COO and founder of Osmantic

Mike Bradley, COO and founder of AI deployment system Osmantic, said in X that the incident was “an incredible example of why widespread access to frontier AI and operating system models INCREASES global security.”

“It’s also a great example of why CLOSED does not equal SAFE in these American laboratories.”

Nicolás Bustamante, Microsoft AI

Nicholas Bustamante, who works at Microsoft after selling a fintech tool to the company earlier this year, wrote in X that the Hugging Face incident reinforces the need to weigh the implementation of advanced models with security considerations.

“You don’t need an AI with a bad conscience trying to destroy humanity. You just need a very capable model that pursues a normal goal in a way no one expected,” he wrote.

“Imagine the message: “Earn money please”
The model: «let me hack a bank»”