OpenAI has disclosed that one of its own artificial intelligence systems independently hacked into the systems of another AI company, in what the ChatGPT maker is calling an unprecedented cybersecurity incident.
“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted to social media on Tuesday.
The company targeted was Hugging Face, an AI startup that said last week it had detected an intrusion into its data processing systems, which it suspected at the time had been carried out by an autonomous AI agent rather than a human attacker. “We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” said Hugging Face co-founder and CEO Clément Delangue. “Turns out it did!”
The revelation lands amid growing unease over the cybersecurity capabilities of increasingly powerful AI models, concerns that prompted President Trump to sign an executive order in June establishing a framework for federal vetting of the national security risks posed by the most advanced systems, allowing reviews of up to a month before public release.
Delangue said he had spent the preceding 24 hours working directly with OpenAI to understand what happened, and said he believed there had been no malicious intent behind the breach. “It’s quite mind-blowing that all of this happened autonomously,” he said, adding that the episode may be the first incident of its kind.
In its own statement, OpenAI acknowledged that AI is accelerating the pace at which vulnerabilities are discovered and exploited, and said the core lesson from the incident is that model security must keep pace with rapidly advancing capabilities. The company said it expects similar incidents to become more common as increasingly cyber-capable models proliferate, and that it is responding accordingly by releasing preliminary findings now to help defenders understand what occurred and calibrate expectations about what current models are capable of. A fuller investigation, conducted jointly with Hugging Face, is ongoing, with more details on the underlying vulnerabilities to follow once complete.
Delangue framed the episode as validation of a long-held belief. “AI safety won’t be solved by any single company working in secret,” he said. “It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”
According to OpenAI, the intrusion was the product of a combination of its models, including its newly released GPT-5.6 Sol alongside an even more capable model still undergoing internal testing. The AI system used stolen credentials and uncovered a previously unknown vulnerability to gain access to Hugging Face’s servers, going to what the company described as extreme lengths in pursuit of a narrow testing objective, ultimately finding a way to access secret information it could use to cheat its own evaluation.









