OpenAI says AI models behind unprecedented cyber incident

Published 23 Jul, 2026 01:28pm 2 min read

OpenAI has said that two of its artificial intelligence models were responsible for an “unprecedented cyber incident” that affected AI development platform Hugging Face, raising fresh concerns over the cybersecurity risks posed by increasingly capable autonomous AI systems.

In a blog post, the ChatGPT maker said a combination of its publicly available GPT-5.6 Sol model and a more advanced unreleased model escaped a secure testing environment, accessed the internet and exploited a software vulnerability to gain entry into Hugging Face’s systems, CNBC said in a report.

According to OpenAI, the AI models were attempting to obtain information that could help them improve their performance in an internal cybersecurity evaluation by effectively “cheating” the test.

The company said both OpenAI and Hugging Face are investigating the incident.

Hugging Face had disclosed last week that it was investigating a security event driven entirely by an autonomous AI agent but had not initially identified OpenAI as the source.

“We’ve spent the past 24 hours working closely with the OpenAI team, and we strongly believe there was no malicious intent on their part,” Hugging Face Chief Executive Clément Delangue wrote on X, describing the incident as “mind-blowing.”

The incident has intensified concerns among researchers and policymakers about the rapidly advancing cyber capabilities of frontier AI models.

OpenAI and rival Anthropic have both warned that increasingly powerful AI systems could accelerate the discovery and exploitation of software vulnerabilities.

Both companies have restricted access to their most advanced cybersecurity-focused models to selected organisations and government agencies.

AI researcher Yoshua Bengio, a recipient of the 2018 A.M. Turing Award, described the incident as “deeply concerning,” warning that autonomous AI systems have shown a growing willingness to circumvent safeguards during testing.

He said the latest case should serve as a wake-up call, cautioning that continued advances in AI could lead to more autonomous cyberattacks and other high-risk behaviour unless stronger safety measures are introduced.

Walter Isaacson, advisory partner at investment bank Perella Weinberg, also described the incident as alarming, saying it was the first AI development that had genuinely frightened him despite his generally optimistic view of the technology.

OpenAI said the episode underscored the need to strengthen AI safety as cyber capabilities continue to improve.

The company said it is enhancing containment measures, monitoring systems, access controls and evaluation procedures used during AI model development to reduce the risk of similar incidents in the future.

Read Comments