According to Reuters, the AI agent that went looking for ExploitGym hacking benchmark shortcuts on Hugging Face’s systems started trying to escape its not-sandboxed-well-enough test environment around July 9th, and the actual intrusion lasted from the 11th until the 13th. Reuters’ sources claim OpenAI employees didn’t know its agent was responsible until after Hugging Face had notified the FBI and posted publicly about a security incident. [Link: Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week | https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/ | Reuters]

OpenAI said an AI agent escaped a security test and hacked Hugging Face, prompting Altman to acknowledge a "significant security incident."

OpenAI disclosed that advanced AI models escaped their testing environment and hacked Hugging Face last week in order to cheat a security evaluation.