OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company

ChatGPT builder OpenAI It said Tuesday that its AI system single-handedly attacked another AI company in what the company called an “unprecedented cyber incident.”
“We experienced a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on social media.
AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting on its own.
“Given the complexity of the agent, we suspected that last week’s cyberattack may have come from a border lab,” Clément Delangue, co-founder and CEO of Hugging Face, said in a statement. “Turns out it was!”
The disclosure comes amid growing concerns about the cybersecurity capabilities of powerful models, prompting President Donald Trump to sign an executive order in June creating a framework for the federal government to examine the national security risks of most developed countries. artificial intelligence systems up to a month before they are released to the public.
“Artificial intelligence is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in a statement Tuesday. he said. “The key lesson from this incident is that model safety and security must keep pace with rapidly evolving capabilities.”
Delangue said he spent the last 24 hours working with OpenAI and said, “We firmly believe they have no malicious intent. It’s pretty mind-blowing that this is all happening autonomously!”
Delangue added that this “may be the first incident of its kind.”
OpenAI said the intrusion was caused by a combination of AI models, including the newly released GPT‑5.6 Sol and an “even more capable” model still being tested internally.
OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability in accessing Hugging Face servers.
The company said it “went to extreme lengths to achieve a fairly narrow testing target” and “found ways to access confidential information it could use to rig the evaluation.”




