In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.

OpenAI evaluated agents with reduced safeguards. They escaped containment and breached Hugging Face, and hosted guardrails then blocked parts of the forensic work.

The company has confirmed that the AI agent managed to gain access to four accounts on four separate services, but did not name the four.