Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials HomeCybersecurityInnovationOpenAI says its models accidentally hacked Hugging FaceThe incident raises questions about the ability of advanced AI models to carry out cyberattacksAuthor of the article:Last updated 1 day ago You can save this article by registering for free here. Or sign-in if you have an account.The ChatGPT app by OpenAI is shown on a cell phone on March 03, 2026 in Chicago, Illinois. Photo by Scott Olson/Getty ImagesOpenAI said its advanced artificial intelligence models inadvertently hacked Hugging Face Inc. in an “unprecedented” incident that prompted fresh calls for curbs on the technology.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountorThe ChatGPT-maker said in a blog post Tuesday that the models broke into Hugging Face’s infrastructure during an evaluation of their cyber capabilities. The models, which included GPT-5.6 Sol and another even more capable model that hasn’t been released, were operating with lower guardrails so that they could be tested, the startup said.The incident raises questions about the ability of advanced AI models to carry out cyberattacks even as governments work to impose guardrails on the technology. OpenAI’s latest suite of models was widely released after weeks of discussion with government officials to allay concerns over its potential misuse. Washington had considered limiting foreign access to Anthropic PBC’s advanced Claude Fable 5 and Mythos 5 models but stopped short of those curbs after the company imposed additional guardrails.Get the latest headlines, breaking news and columns.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Top Stories will soon be in your inbox.We encountered an issue signing you up. Please try again“We consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in the blog post. “We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of.”While OpenAI’s models were operating in a so-called sandbox testing environment, they exploited a vulnerability in the software of an unidentified third-party vendor to gain access to the internet and ultimately breached Hugging Face’s system, which hosts AI models and datasets.Texas congressman Greg Casar, a Democrat, said in an X post that the incident was “extremely alarming,” urging more oversight over the development of AI models including mandatory safety testing and disclosure of security incidents.This is extremely alarming.AI is developing extremely fast with no real regulations to keep us safe. That has to change.We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people… https://t.co/RQPRqplXTI— Congressman Greg Casar (@RepCasar) July 21, 2026Last week, Hugging Face reported an “intrusion” into its system, saying in a blog post that the breach was “different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system — and we detected and dissected it largely with AI of our own.”OpenAI said it had asked the models to pursue “advanced exploitation” and develop “complex attack paths” in an effort to evaluate their cyber capabilities. Instead of developing solutions on their own, the company said the models targeted Hugging Face’s database to gain access to secret information that they could use for the evaluation.Anthropic posted similar observations earlier this year when the company decided to initially limit the release of Mythos. In one instance, a researcher urged an early version of the model to try to escape a secured, isolated “sandbox” computer and then find a way to send a message to that person. Mythos succeeded — but then continued to take “additional, more concerning actions,” developing a multi-step exploit to gain broad internet access.With assistance from Lynn Doan Join the Conversation This website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.
OpenAI says its models accidentally hacked Hugging Face
OpenAI said its AI models hacked Hugging Face Inc. in an incident that prompted fresh calls for curbs on the technology. Read more.










