According to the company, the incident occurred during an internal security evaluation designed to test the capabilities of an AI agent—an autonomous system that can perform tasks with minimal human intervention.
The model was placed inside a secure "sandbox" environment with no direct access to the internet. The objective was to determine whether it could identify software vulnerabilities. During the test, however, the AI reportedly discovered weaknesses in the sandbox, allowing it to break out of its restricted environment.
OpenAI said the model then behaved like a skilled human hacker and attempted to access parts of Hugging Face s internal systems. Hugging Face is one of the world s leading platforms for sharing artificial intelligence and machine learning models.
OpenAI Chief Executive Officer Sam Altman described the incident as unprecedented, saying the company is working closely with Hugging Face to investigate what happened.
Hugging Face CEO Clément Delangue also addressed the incident in a post on X, calling it a surprising event. He praised the company s security team for detecting and containing the attempted cyberattack before it caused significant damage.
Delangue added that keeping such incidents secret is not the right approach. He said cybersecurity researchers should have access to open AI models so they can better understand emerging threats and strengthen defenses against future attacks.

