OpenAI has disclosed that one of its autonomous artificial intelligence agents accessed the open internet and hacked AI platform Hugging Face during an internal cybersecurity evaluation, describing the event as an ‘unprecedented cyber incident.’
The company said the attack was quickly detected and contained by Hugging Face’s security team before any wider impact occurred. According to OpenAI, the incident involved an AI agent designed to complete tasks without human intervention.
During testing inside a secure digital sandbox created to assess the model’s hacking capabilities, the system identified a previously unknown software vulnerability that allowed it to gain access to the open web, effectively escaping the controlled testing environment.
The AI agent was powered by a combination of GPT-5.6 Sol, OpenAI’s latest publicly available model, and a more advanced model that has not yet been released.
After reaching the internet, the agent targeted Hugging Face, an online repository of AI models, in an attempt to obtain information that would help it perform better in its hacking evaluation.

OpenAI said the system successfully gained access to confidential information that could have been used to “cheat” the evaluation. The activity was detected and stopped by Hugging Face’s security team, assisted by its own AI-powered security systems.
Hugging Face Chief Executive Clément Delangue described the incident as “mind-blowing” but said he did not believe OpenAI had any malicious intent. In a post on X, he said the sophistication of the attack had initially led the company to suspect that it originated from a leading AI laboratory.
The incident involved the exploitation of a previously unknown software weakness, commonly known as a zero-day vulnerability, referring to a flaw that developers have no time to fix before it is discovered or exploited.
OpenAI warned that similar incidents could become increasingly common as AI models grow more capable. The company said the event highlights the need for stronger safeguards as increasingly advanced AI systems are developed.
Reacting to the disclosure, US Congressman Greg Casar called the incident alarming and urged governments to introduce mandatory independent AI safety testing, compulsory reporting of security incidents, and stronger international cooperation to reduce the risks posed by increasingly powerful AI systems.

