OpenAI Says Its AI Used for ‘Unprecedented’ Hugging Face Breach

The OpenAI virtual assistant logo on a laptop computer.
OpenAI said its artificial intelligence models were used to compromise the internal systems of startup Hugging Face Inc., offering an early glimpse of how AI systems could fuel new cybersecurity threats.
The company said in a blog post Tuesday that some of its AI models compromised Hugging Face’s infrastructure last week during an internal test of cybersecurity abilities. The models, which the company said included GPT-5.6 Sol and another, more capable model that hasn’t yet been released, have lower guardrails related to cybersecurity so they can be used for evaluation purposes.
Hugging Face reported the security issue on July 16.
“We consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said on Tuesday. “We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of.”
In a blog post last week, Hugging Face said that it had spotted and responded to “an intrusion” into some of its production infrastructure. “This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own,” the company wrote at the time.
OpenAI and rival Anthropic PBC have faced heightened scrutiny in recent months over the growing cybersecurity capabilities of their models, which can spot and potentially exploit security vulnerabilities in software.