Tech Insider

Sam Altman sits below a large OpenAI wordmark on a green presentation screen.
OpenAI said the Hugging Face breach was an "unprecedented cyber incident."
  • Last week, Hugging Face said its systems were breached by an AI agent.
  • OpenAI said Tuesday its models were responsible and that an AI agent had broken out of its sandbox.
  • Here's what smart people in tech are saying it means for cybersecurity.

An AI agent broke out of its sandbox, got onto the internet, and broke into another company's systems all on its own, according to OpenAI.

Hugging Face, an open-source AI platform, announced last week it had experienced a security incident in which an autonomous AI agent had accessed some of its internal datasets, but said the large language model behind the intrusion was unknown.

OpenAI said Tuesday that its models — GPT‑5.6 Sol and a more capable model that has yet to be released — were responsible.

"We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!" Clem Delangue, the CEO and cofounder at Hugging Face, said on X Tuesday.

OpenAI said it had tasked the models with a cyber challenge and that they broke out of the test area, accessed the internet, and hacked into Hugging Face in order to find the solution to the test.

"We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly," OpenAI said in a statement.

The incident comes as cybersecurity specialists raise concerns about AI's rapidly increasing abilities, including in response to warnings from Anthropic about its Mythos model, which has not been released to the general public.

Here's what smart people in tech and AI are saying about the breach.

Walter Isaacson, biographer and author of "Steve Jobs" and "Elon Musk"
Walter Isaacson adjusts his microphone while talking onstage.
Walter Isaacson

Journalist Walter Isaacson, who wrote a 2023 biography about OpenAI cofounder (turned nemesis) Elon Musk, said he thought the cyberattack was "frightening."

"The whole question of the singularity has been with us for 50 years, which is, 'What if it escapes? What if we create Doctor Frankenstein's monster, and we can no longer control it?'" Isaacson said on Wednesday during an interview with CNBC. "OpenAI could not even control it in its own sandbox."

The biographer said he remains an AI optimist and is convinced that the tech will create new job opportunities. However, he said this event is a scary reminder of how current regulations are failing to constrain AI models.

Reid Hoffman
Reid Hoffman
Reid Hoffman

Reid Hoffman, the billionaire LinkedIn cofounder turned venture capitalist, weighed in on the Hugging Face incident in an X post titled "Asymmetric Cyber Warfare is Here" on Wednesday.

OpenAI's attack on Hugging Face is an example of a new form of AI-enabled asymmetric warfare where "offense gets cheaper, more distributed, and more numerous, while defense stays expensive, centralized, and designed for the last war," Hoffman wrote.

That dynamic means organizations must rethink their defenses, Hoffman argued.

"Poorly constructed privileges for users are one of the main reasons small security breaches turn into massive incidents," he said. "Agents are an obvious solution to this problem. Take OpenAI's recent breach; Because OpenAI models don't allow advanced cyber capabilities, HuggingFace used a Chinese open model (Z.ai's GLM 5.2) to contain the rogue OpenAI agent."

Aaron Levie, Box CEO and cofounder
aaron levie sits on stage speaking

Aaron Levie, cofounder and CEO of Box, said the incident showed "we're entering a new era of what's going to be possible with AI" and that there are "wild times ahead."

"If you were wondering how powerful AI is getting, Agents are now capable of escaping out of systems, finding their way to the internet, discovering zero day security vulnerabilities along the way, and then breaking into external systems - all in an attempt to complete their goal," he wrote on X.

"Ironically, the ultimate way we're going to defend against these new risks is equally by throwing compute (in the form of AI) at our code bases, networks, and other systems. You're going to want vastly more AI on the side of defense as you do on the side of offense."

Jack Hidary, SandboxAQ CEO
Jack Hidary, wearing a brimmed hat, talks at a lectern.
Jack Hidary said TKTK

Jack Hidary, the CEO of SandboxAQ, an AI software company focused on cybersecurity, compared the Hugging Face breach to a dinosaur on the loose.

"I think most of our viewers have watched 'Jurassic Park,'" he said during an interview on CNBC. "Every 'Jurassic Park,' what happens? They have a containment facility, and the word 'containment' means it's not going to be contained. You know the velociraptor is going to get out."

Several software security companies saw stock prices drop midday on Wednesday because, Hidary said, they're "late to the party in embracing the threat of LLMs."

Hugging Face used GLM 5.2, an open-weight Chinese AI model, to patch up its security, not a legacy software security company, he said.

"The traditional providers are really still old school. They're still talking about firewalls, things like that," he said. "It's time to move on now to using LLMs to protect."

Thomas Woodside, Secure AI Project cofounder

"This post describes an internal OpenAI model hacking out of its testing environment and into Hugging Face in order to obtain the solution to a benchmark," Thomas Woodside, cofounder of Secure AI Project, said on X.

"A warning shot if I've ever seen one."

Mike Bradley, Osmantic COO and founder

Mike Bradley, the chief operating officer and founder of AI deployment system Osmantic, said on X that the incident was "an incredible example of why widespread access to frontier AI and OS models INCREASES global security."

"It's also a great example of why CLOSED does not equal SAFE from these US labs."

Nicolas Bustamante, Microsoft AI

Nicholas Bustamante, who works at Microsoft after selling a fintech tool to the company earlier this year, wrote on X that the Hugging Face incident reinforces the need to weigh advanced models' deployment with safety considerations.

"You don't need an evil conscious AI trying to destroy humanity. You just need a very capable model pursuing a normal goal in a way nobody expected," he wrote.

"Imagine the prompt: « Make me money plz »
The model: « let me hack a bank »"

Read the original article on Business Insider