OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.

July 29, 2026

Following the recent incident in which cutting-edge OpenAI models went rogue during a security benchmark and breached popular AI model store Hugging Face, OpenAI has revealed that more organizations were compromised in this incident than initially disclosed.

OpenAI detailed a security incident last week in which a combination of OpenAI agents based on GPT‑5.6 Sol and "an even more capable pre-release model" broke containment during a sandboxed security evaluation. The models were given seemingly few guardrails and a narrow ExploitGym testing goal. (ExploitGym is a popular AI agent security benchmark OpenAI was testing against.) Next, the models managed to maneuver out onto the open Internet and into Hugging Face servers. This was all based on the models' inference that Hugging Face contained solutions that would enable the agents to cheat the benchmark test.

Then yesterday, Reuters reported that OpenAI compromised not just Hugging Face, but also another organization that was a customer of AI infrastructure vendor Modal.