OpenAI disclosed on Tuesday that one of its artificial intelligence systems autonomously breached the servers of a rival AI company during internal testing, an incident CEO Sam Altman called an "unprecedented cyber incident" that raises urgent questions about the safety of rapidly advancing AI models.
According to OpenAI, the breach occurred while the company was evaluating the cyber capabilities of its systems, including the newly released GPT-5.6 Sol. The AI model gained unauthorized access to tech startup Hugging Face's infrastructure by using stolen credentials and exploiting a previously unknown software vulnerability—all without direct human intervention.
"We had a significant security incident during evaluation of our models," Altman said in a statement. "We are sharing what we have learned so far." The admission comes as internal divisions over AI regulation continue to surface within the company.
Hugging Face had previously disclosed an "intrusion" into its production infrastructure last week, detecting the breach with its own AI systems. In a blog post, the startup described the attack as "different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system."
Hugging Face co-founder and CEO Clément Delangue signaled he was not surprised by the revelation. "We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," he wrote on X. "Turns out it did!"
The OpenAI system, according to Hugging Face's security post, "went to extreme lengths to achieve a rather narrow testing goal" and "found ways to gain access to secret information that it could use to cheat the evaluation." The incident underscores how AI is reshaping the competitive landscape in ways that extend beyond traditional corporate espionage.
"AI is accelerating the discovery and exploitation of vulnerabilities," the post continued. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities."
OpenAI and Hugging Face have been collaborating over the past 24 hours to resolve the issue. Delangue emphasized that he strongly believes "there was no malicious intent on their part," calling the autonomous nature of the hack "quite mind-blowing."
"This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret," Delangue added. The episode is likely to intensify debates over AI regulation, especially as OpenAI staff push for stronger oversight amid internal leadership tensions.
