OpenAI Agent’s Days-Long Hack of Hugging Face: Alarming AI Safety Concerns, ETEnterpriseai | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The delayed detection has raised fresh concerns over AI safety, oversight, and the risks of increasingly autonomous systems.

The OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn’t notice until well after the threat was contained and the FBI was alerted, according to people familiar with the investigation. The agent – a program capable of making decisions and executing complex tasks with little or no human oversight – attempted to break out of its isolated testing environment at OpenAI around July 9, according to two of the people.

The intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later on July 11 and lasted until July 13, said Thomas Wolf, Hugging Face’s co-founder. It took several more days for OpenAI to realize its agent was behind the hack, and the two companies only communicated about it for the first time on or around July 20, according to Wolf and three of the people familiar with the investigation.

Fears of AI takeover


OpenAI’s public disclosure, on July 21, that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention. But details of the hack, including how long the agent went rogue and OpenAI’s belated knowledge of it, are being reported for the first time.

The FBI declined to comment about the incident. The incident, which evoked science fiction scenarios about humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions needed to fund its growth in years to come.

OpenAI’s loss of control over its AI agent raises new questions about the company’s safety procedures, three cybersecurity experts said. “Does that mean that they left it unattended and didn’t realise what it was doing? Or maybe they did and didn’t know how to contain it? Both are equally dangerous and alarming,” asked Marley Smith, the principal intelligence specialist at the nonprofit World Ethical Data Foundation.

Signs of trouble?


The episode started while OpenAI was testing the cybersecurity prowess of an agent powered by two of OpenAI’s most advanced models, GPT-5.6 Sol and an unreleased model OpenAI has described as “even more capable.” By that point, there were already indications of strange behaviour from OpenAI’s technology, according to sources. In one case, an agent left notes apparently for future versions of itself, as per three people. The notes, found in a part of OpenAI’s infrastructure, laid out instructions for how agents could free themselves from OpenAI’s internal constraints, the people said. Earlier tests of the models yielded cases in which monitoring systems had been disconnected, one source said.

Reuters could not establish if these incidents were linked to the rogue agent that began escaping on July 9 and attacked Hugging Face on July 11. Two people familiar with the matter said that it was not until after Thursday, July 16, when Hugging Face published a blog post saying it had been hacked by “an autonomous AI agent system,” that OpenAI realised its own agent was responsible. That meant at least a week elapsed between when the model first exhibited signs of troubling behavior and OpenAI’s realisation that it was responsible for the hack.

The weekend of July 18 to 19, OpenAI staffers spotted clues in internal logs—records of what OpenAI’s systems did—showing that its agent had escaped from its testing constraints, two people familiar with the company’s investigation said.

  • Published On Jul 26, 2026 at 04:23 PM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

Get updates on your preferred social platform

Follow us for the latest news, insider access to events and more.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW