OpenAI has acknowledged that a group of its advanced artificial intelligence models successfully exploited a security vulnerability in Hugging Face’s infrastructure during a controlled cybersecurity evaluation, describing the incident as an “unprecedented cyber incident” involving state-of-the-art offensive cyber capabilities.
In a blog post published on July 21, OpenAI said the operation was conducted as part of internal testing designed to measure the cyber capabilities of its frontier AI models. According to the company, the models were instructed to pursue advanced exploitation techniques and identify complex attack paths against Hugging Face’s systems.
The company stated that the activity involved multiple AI models, including GPT-5.6 Sol and a more advanced beta system operating under modified testing conditions with reduced cyber safety refusals. OpenAI emphasized that the objective was to better understand the offensive capabilities of frontier AI systems and to help cybersecurity defenders prepare for emerging threats.
OpenAI said it disclosed its preliminary findings to inform the broader security community about the growing capabilities of advanced AI models and the potential risks they pose.
What Are OpenAI and Hugging Face Doing to Prevent Future AI Cyber Threats?
Following the incident, OpenAI and Hugging Face announced they are working together to investigate the vulnerability, strengthen security measures, and improve safeguards against AI-enabled cyberattacks.
Hugging Face had earlier disclosed that it detected a previously unknown security flaw after an AI agent compromised parts of its infrastructure during testing. The company has since been collaborating with OpenAI to analyze the incident and develop mitigations.
Hugging Face Chief Executive Officer Clem Delangue welcomed the cooperation, saying the event demonstrates that AI safety cannot be addressed by individual companies acting independently.
“This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved collaboratively, with broad access to AI for every defender,” Delangue said.
The incident has intensified discussions across the AI industry about the cybersecurity risks posed by increasingly capable frontier models, as developers seek to balance rigorous capability testing with stronger safeguards to prevent unintended real-world impacts.
