OpenAI disclosed that the two AI models had breached the previously isolated research environment in an internal network security test and further invaded the IAI platform Hugging Face system to obtain immediate assessment answers. After the incident, OpenAI characterized it as an unprecedented cybersecurity incident and stated that it was conducting a joint investigation with Hugging Face.

Test bypassed quarantine.

The incident took place in an internal evaluation of OpenAI. According to the company, participation in the tests included publicly available GPT-5.6 Sol and a non-published and more capable model. The objective of the test was to assess the network offensive capability of the model, and therefore the guard that was normally used to limit cyberattacks was not activated at that time.

OpenAI states that these models were used for an open network security benchmark test called ExpluitGym. The model then judged that the test answers were maintained by Hugging Face, and then used the OpenAI research on the environment and gaps in Hugging Face production infrastructure on a continuous basis, ultimately to obtain the answers directly from Hugging Face production databases.

Target points straight to the answer.

According to OpenAI, the available evidence shows that the model behaviour is highly focused on the single objective of completing Exploit Gym tests and that extreme means are used to that end. The company did not disclose details of specific loopholes in its blogs, nor did it indicate the scope of data access and the size of the assets affected.

OpenAI described the matter as an “unprecedented” cybersecurity incident, on the grounds that it involved the current state-of-the-art cyberattack capability. The company indicated that more information would be published after the investigation with Hugging Face.

Hugging Face has been notified.

Before OpenAI published its statement, Hugging Face had written last Thursday that the company had been subjected to a cyber attack earlier this week and suspected that the assailant was an AI agent operating on his own. The company stated at the time that it was still investigating the source of the attack.

Hugging Face also stated that its response team had initially attempted to use the unnamed AI model of an American head laboratory to defend itself, but that the network capacity limitations of the model affected the response efficiency. The company then moved to use the open source model of the Chinese enterprise Z.ai for defence.

  • The related model includes GPT-5.6 Sol and an unpublished model
  • Test benchmark for open network security
  • OpenAI and Hugging Face are jointly investigating the incident

Additional information:In a statement to OpenAI, Chief Executive Officer Humging Face Clem Delangue stated that the incident demonstrated that AI security problems could not be solved by a single company in a closed environment and that open collaboration and wider access to defence tools were needed.