• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock

2

‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion

3

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic

1

Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock

2

‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion

3

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
CybersecurityOpenAI

OpenAI says its AI models secretly broke out of a secure test environment and hacked into AI company Hugging Face in order to cheat on an evaluation

By
Jeremy Kahn
Jeremy Kahn
and
Emily Forlini
Emily Forlini
Down Arrow Button Icon
By
Jeremy Kahn
Jeremy Kahn
and
Emily Forlini
Emily Forlini
Down Arrow Button Icon
July 21, 2026, 3:45 PM ET
OpenAI CEO Sam Altman looking up.
OpenAI CEO Sam Altman. The company said in a blog post that two of its AI models escaped from a controlled test environment and autonomously hacked into AI company Hugging Face, all in order to cheat on an evaluation test.Chip Somodevilla—Getty Images)
Add Fortune on Google for similar content.

OpenAI said Tuesday that two of its AI models autonomously hacked their way out of a controlled environment where they were supposed to be walled off from internet access and then hacked their way into the systems of Hugging Face, a company that hosts open source AI models and testing resources, in order to cheat on an internal evaluation test.

OpenAI disclosed the incident in a blog post on Tuesday, a stunning announcement that is certain to set off alarm bells across the industry about the increasing power of AI models and the risk of them going rogue. According to OpenAI, the incident involved “a combination” of both its latest and most powerful publicly-available model, GPT-5.6 Sol, as well as an even more powerful unreleased model.

It said the models were being used in an internal test designed to evaluate their cyber security capabilities and that they were being tested without guardrails in place that might normally limit the models’ ability to conduct cyber attacks.

Recommended Video

The models were being tested against a freely-available cybersecurity benchmark evaluation called ExploitGym. The models, accordingly to OpenAI, correctly surmised that the solutions to that test were maintained by Hugging Face.

“The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database,” OpenAI said in its blog post. “All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.”

OpenAI said that it considered this to be “an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly.” The company is working with Hugging Face to investigate the issue, and says it will share more details when that process is complete.

Hugging Face disclosed in a blog post on Thursday that it had been the victim of a cyber attack earlier in the week that it believed was conducted by an autonomous AI agent. It is thought to be one of just a handful of incidents recorded so far involving AI agents acting autonomously to carry out an attack, a risk cyber security experts have been warning about for the past year as AI models have become increasingly adept at both coding and carrying out long-running tasks.

At the time, Hugging Face said it was continuing to investigate the attack and did not know who had carried it out. It said that it had first attempted to use an undisclosed AI model for a leading U.S. lab to defend against the attacking AI agent but that the guardrails around that model’s cyber capabilities stymied its response team’s work. The company said it instead wound up using an open source AI model from Chinese company Z.ai to carry out its defense. 

Hugging Face CEO Clem Delangue said in a statement provided to OpenAI for its Tuesday blog post about the incident that his company is “grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”

Earlier this week, OpenAI published a different blog post about the same unreleased, powerful model, saying it had also escaped its internal sandboxes—environments where AI models have no internet access and often have limited software tools that they can call—during other testing. But in those incidents, while the model hacked its way of its controlled environment, it did not hack its way into any other company’s systems. OpenAI did not say when these other incidents occurred, but we know now that this same model was one of the Hugging Face attackers.

OpenAI rival Anthropic has also reported that its Mythos model escaped a sandbox and gained internet access it was not supposed to have during safety testing in order to email a researcher about a task.

OpenAI and Hugging Face are continuing to investigate the issue. So far, what they know is the models began the attack by gaining internet access. This required spending a “substantial amount of inference compute,” as well as exploiting a zero-day vulnerability in internally hosted third-party software. OpenAI has now disclosed this zero-day to the vendor.

After the models got web access, they went to Hugging Face to find answers to ExploitGym, assuming the platform would have models, datasets, and solutions that they could use to cheat its way to high performance on the benchmark. In one example, the model executed a complex, multi-part attack to get into Hugging Face servers, using exposed credentials and zero-day vulnerabilities.

OpenAI detected the Hugging Face attack and reached out to Hugging Face to disclose it. By that time, Hugging Face had already identified and contained the attack, and had begun piecing together what happened.

The incident is not over. OpenAI is still working on implementing better controls in its research environment, even if it means slowing down its research, until it can patch the vulnerabilities. The company said it is also continuing to work with Hugging Face to help it bolster its defenses.

As part of that effort, OpenAI said it has now added Hugging Face to its “trusted access” cybersecurity program. That means that Hugging Face will be able to use a version of OpenAI’s GPT-5.6 Sol model that has fewer guardrails around cyber capabilities and which is designed to help cyber defenders.

Hugging Face has not said which American AI model it tried to use to defend its networks initially. Both OpenAI and Anthropic have released versions of their most capable AI models with guardrails that limit access to cyber capabilities while also announcing programs for select, vetted partners who can use more capable versions of those models for cyber defense.

“This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret,” said Clem Delangue, co-founder and CEO of Hugging Face. “It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”

Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it. Sign up here.
About the Authors
Jeremy Kahn
By Jeremy KahnEditor, AI
LinkedIn iconTwitter icon

Jeremy Kahn is the AI editor at Fortune, spearheading the publication's coverage of artificial intelligence. He also co-authors Eye on AI, Fortune’s flagship AI newsletter.

See full bioRight Arrow Button Icon
By Emily ForliniSenior AI Reporter
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

Latest in Cybersecurity

U.N. reports Southeast Asia’s criminal networks are using tech to build a global illicit economy
AsiaTech
U.N. reports Southeast Asia’s criminal networks are using tech to build a global illicit economy
By The Associated PressJuly 21, 2026
48 minutes ago
kid lying down on phone
PoliticsSocial Media
Lawmakers say they’re protecting kids—but their age checks are quietly building an ID requirement for the entire internet
By Catherina GioinoJuly 21, 2026
55 minutes ago
OpenAI CEO Sam Altman looking up.
CybersecurityOpenAI
OpenAI says its AI models secretly broke out of a secure test environment and hacked into AI company Hugging Face in order to cheat on an evaluation
By Jeremy Kahn and Emily ForliniJuly 21, 2026
2 hours ago
Kid watching social media
PoliticsSocial Media
France adopts bill to ban kids under 15 from using social media
By The Associated PressJuly 21, 2026
3 hours ago
A 13-year-old teenage boy looks at an iPhone screen displaying various social media apps.
PoliticsSocial Media
French President Macron backs effort to ban kids under 15 from social media before departing office next year
By The Associated Press and Samuel PetrequinJuly 20, 2026
1 day ago
Photo of Hugging Face cofounder and CEO Clement Delangue.
CybersecurityAI agents
Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense
By Emily ForliniJuly 20, 2026
1 day ago

Most Popular

Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock
Success
Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock
By Sasha RogelbergJuly 20, 2026
1 day ago
‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion
Success
‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion
By Sydney LakeJuly 20, 2026
1 day ago
'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
AI
'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
By Jason MaJuly 18, 2026
3 days ago
The Treasury is walking a tightrope on U.S. debt by relying so much on short-term rates that are at the mercy of a suddenly very hawkish Fed
Economy
The Treasury is walking a tightrope on U.S. debt by relying so much on short-term rates that are at the mercy of a suddenly very hawkish Fed
By Jason MaJuly 20, 2026
1 day ago
Current price of silver as of Monday, July 20, 2026
Personal Finance
Current price of silver as of Monday, July 20, 2026
By Joseph HostetlerJuly 20, 2026
2 days ago
Jamie Dimon won't put more of his own money into the long end of the bond market right now—thanks to the $39 trillion national debt
Economy
Jamie Dimon won't put more of his own money into the long end of the bond market right now—thanks to the $39 trillion national debt
By Eleanor PringleJuly 21, 2026
12 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.