The real lesson of the Hugging Face breach isn't that AI went rogue—it's how self-serving hype steers regulators toward the wrong fixes.

OpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.

OpenAI’s models were told to find and exploit vulnerabilities. They did — on a company that was never part of the exercise.