OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.

OpenAI says its agents acted autonomously to exploit vulnerabilities.

OpenAI has come forward to claim responsibility for the Hugging Face breach, saying it was the result of internal testing gone awry.