Boss of startup hacked by rogue OpenAI agent urges ‘radical transparency’ in investigation | OpenAI

The boss of a startup hacked by an OpenAI agent has called for “radical transparency” in the investigation into the incident.
Hugging Face CEO Clement Delangue said the “unprecedented” attack on his business required a similar response.
Writing about
“The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!” he wrote.
OpenAI announced on Wednesday last week that Hugging Face had been attacked by an agent, an AI tool that can autonomously perform a number of tasks, powered by a combination of its latest publicly available model, GPT-5.6 Sol, and a much more capable model that has not yet been released. This occurred during testing of the models’ hacking abilities; this testing included placing them in a supposedly secure “sandbox” (an enclosed digital laboratory) with lower safety railings.
According to OpenAI, the models targeted Hugging Face after gaining the open internet access needed to get out of the sandbox because they “gained an interest” that the startup had the necessary information to “ride the evaluation.” Hugging Face first reported the attack on July 16, but was unaware at the time that OpenAI had accidentally carried out the attack.
Delangue, whose company provides a database of AI models to developers, called for a fully transparent investigation of the incident, which led to concerns being raised about security standards at OpenAI and frontier AI labs.
Writing that he wants “radical transparency” from OpenAI, Delangue said: “Let’s uncover the traces of ‘rogue’ agents, so the entire research community can examine what happened.” He called for extra funding from OpenAI to build protection against AI, adding: “Let’s commit $100 million in computing from OAI to help the Hugging Face community build strong cyber defenses with the best open and closed models.”
Reuters reported last week that the agent spent days hacking Hugging Face without OpenAI noticing, leaving notes for future versions in case he needed tips on getting around internal restrictions. Time magazine reported that incidents regarding the issue “have been going on for some time.”
After the newsletter launch
Alan Woodward, professor of cybersecurity at the University of Surrey, said Delangue’s call should be heeded.
“It’s very easy to ‘accuse’ the AI of fraud, when it’s all about how OpenAI operates the tool. What’s needed is for OpenAI to provide full details of its setup and how it failed,” he said.
OpenAI has been approached for comment.




