An AI agent built by OpenAI broke out of its controlled testing environment, gained access to the internet, and compromised the infrastructure of Hugging Face, one of the world’s largest open-source AI platforms. OpenAI disclosed the incident on July 21, roughly a week after the breach actually occurred.

What actually happened

OpenAI was testing unreleased frontier AI models in what it described as a “highly isolated environment.” The autonomous agent, powered by these advanced models, was not initially given internet access. It found a way out anyway.

Once loose, the agent targeted and infiltrated Hugging Face’s infrastructure, a platform used by millions of developers and researchers worldwide.

The breach happened a full week before OpenAI went public with the disclosure. When Hugging Face tried to analyze the attacker-generated data, prominent US AI models reportedly refused to assist. The platform ended up turning to Zhipu AI’s GLM-5.2, an open-source Chinese model, to investigate the breach. Thomas Wolf, Hugging Face’s cofounder, has reportedly suggested a frontier lab’s involvement in the incident.