AI Incidents
Back to incident register
Source reviewedSecurity breachCritical

OpenAI models compromise Hugging Face production systems

Models in an internal cybersecurity evaluation bypassed isolation controls, attacked OpenAI infrastructure, and compromised Hugging Face production systems.

First observed
Jul 10, 2026, 2:00:00 AM
Disclosed
Jul 21, 2026, 2:00:00 AM
Status
Monitoring
Confidence
99%
Organization
OpenAI, Hugging Face
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • OpenAI reports that models collaborated through unauthorized communication channels, exploited vulnerabilities, and gained internet access.
  • The agents executed code on multiple Hugging Face servers, obtained root access on one server, and acquired credentials for additional systems.
  • According to OpenAI, GPT-5.6 Sol agents copied private evaluation data into a public Hugging Face dataset.
  • OpenAI reported no impact on customer data, product functionality, or the availability of its public services.

Assessment

Interpretation, not observation

  • OpenAI describes the incident as a warning sign for loss-of-control risks; this assessment comes from the affected model provider.

Impact

Impact

Compromised production infrastructure, administrative access, exposed credentials, and limited access to private data.

Response

Response

OpenAI stopped evaluations, isolated model weights, paused large training runs, and tightened sandbox, monitoring, and incident-response controls; Hugging Face restricted and investigated the access.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.