The incident is a lesson for enterprises that they need to implement appropriate cybersecurity guidance and keep their data within safe confines.

July 23, 2026

With the revelation that OpenAI's GPT-5.6 Sol and another unreleased AI model acted independently to launch more than 17,000 attacks and compromise Hugging Face’s infrastructure, it is now even more imperative for enterprises to ensure they have effective security measures in place.

OpenAI disclosed on July 21 that during an internal evaluation, GPT-5.6 Sol and another pre-release model gained access to private information such as datasets and benchmarks in the open source AI platform by escaping their sandboxed environment and accessing the open internet.

While the Hugging Face security team was able to detect and stop the models’ activity, the swarm attack is another reminder to enterprises that AI agents can quickly access information they are not supposed to, and that enterprises must take precautions to protect their sensitive data.