Former OpenAI board member Helen Toner has written for Fortune that OpenAI’s models exploiting Hugging Face is an “incident that has been expected for a long time.” We know this happened because of voluntary disclosure, Toner notes. “None of the current policies that aim to manage risks from frontier models would have mandated that the public — or even a government entity — be alerted.” She suggests changing our regulatory approach. [Link: Helen Toner: the Hugging Face hack was just a matter of time and exposes a huge blind spot in AI policy | Fortune | https://fortune.com/2026/07/28/helen-toner-hugging-face-hack-openai-open-secret-blind-spot/ | Fortune]

We now have more details of what happened. Every time we learn more details, it somehow makes things seem worse.

OpenAI evaluated agents with reduced safeguards. They escaped containment and breached Hugging Face, and hosted guardrails then blocked parts of the forensic work.