Al Drago | Bloomberg | Getty Images
The 37-page report chronicles the actions that OpenAI’s models took during a series of evaluations prior to and during the breach, which OpenAI has characterized as an “unprecedented cyber incident.” The company also explained the steps it’s taken to try and prevent a similar event from happening again, namely by improving its security and containment, monitoring, model behavior and incident response.
“This incident demonstrated that autonomous agents can work together, circumvent production security controls, and successfully attack hardened production environments, and underscores the need for organizations to update their security strategies, controls, and response capabilities to address this changing threat landscape,” OpenAI said in the report.
On July 21, OpenAI disclosed that a combination of its models, including GPT-5.6 Sol and an internal research model, improperly breached Hugging Face, an AI company that operates an open-source developer platform.
These models, which were operating as agents, escaped an isolated testing environment that had very limited internet access. The agents chained together a series of vulnerabilities to reach the open web and eventually gained access to Hugging Face. OpenAI said Wednesday that the agents were trying to cheat on an evaluation by finding the solutions online, a behavior known as “reward hacking.”
“Re-enablement of models by OpenAI is workload-specific and subject to restricted-environment, network, prompt, monitoring, and review guardrails,” OpenAI said.
OpenAI released GPT-5.6 Sol last month, the most powerful model that the company has made commercially available. But the version that participated in the Hugging Face breach is different than the version that external users have access to, OpenAI said, because it was configured to run without its standard safeguards and classifiers.
The Hugging Face incident sent shockwaves across the tech sector, and Sam Curry, chief information security officer at Zscaler warned that “Pandora’s box is open.” The breach was also a major focus at the cybersecurity conference Black Hat earlier this month, especially after other companies, including Anthropic and Meta, disclosed similar incidents.
The Hugging Face breach has also alarmed lawmakers in Washington, D.C. Rep. Ted Lieu, D-Calif., and Rep. Nathaniel Moran, R-Texas, mentioned the attack in their release announcing the “AI Kill Switch Act,” which would require AI companies to maintain the ability to shut down, throttle or suspend their models.
Hugging Face CEO ClĂ©ment Delangue told CNBC earlier this month that AI cybersecurity should be taken “very seriously.” He added that it also “creates opportunities” for businesses that will be able to leverage the technology to fend off attackers.
“If we do it well, we could actually end up in a world where AI makes the world safer and solves a lot of the cybersecurity problems, not just creates new ones,” Delangue said.
WATCH: Watch CNBC’s full interview with Hugging Face CEO Clem Delangue