Description: OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
Editor Notes: Timeline notes: The incident ID date is 07/11/2026, inferred from Hugging Face's statement that the intrusion involved lateral movement during the weekend preceding its 07/16/2026 disclosure. OpenAI publicly attributed the activity to its evaluation models on 07/21/2026. The incident ID was created on 07/22/2026.
Entities
View all entitiesAlleged: OpenAI , AI agent system developers and Large language model developers developed an AI system deployed by OpenAI and AI agent system deployers, which harmed OpenAI and hugging face.
Alleged implicated AI systems: GPT-5.6 Sol , Unidentified pre-release OpenAI model , AI agent system , Large language models , OpenAI large language models , ExploitGym , OpenAI research testing infrastructure and Hugging Face production infrastructure
Incident Stats
Incident ID
1604
Report Count
3
Incident Date
2026-07-11
Editors
Daniel Atherton
Incident Reports
Reports Timeline
Loading...
Hugging Face post-incident response
Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent s…
Loading...
OpenAI post-incident response
Last week, Hugging Face disclosed a new kind of security incident(opens in a new window)after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferat…
Loading...
Yesterday, OpenAI made an alarming disclosure: An assortment of its most advanced AI models, including one that has not yet been released, had autonomously broken out of the company's internal systems and hacked into the databases of anothe…
Variants
A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?