OpenAI, the company that makes the ChatGPT chatbot, has revealed that its artificial intelligence (AI) models autonomously breached another company’s production systems in what it called an “unprecedented cyber incident.”
The ChatGPT maker said in a July 21 blog post that the models—including its newly released GPT‑5.6 Sol and a more capable model still undergoing internal testing—compromised infrastructure operated by AI platform Hugging Face after escaping a restricted environment in which a cybersecurity evaluation was being conducted.
“The model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation,” OpenAI said.
In one case, the model assembled multiple attack vectors into a single cyber-strike, cobbling together stolen credentials with zero-day vulnerabilities on the Hugging Face servers before exploiting a remote code execution path to carry out a breach.
“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said.
The company released its preliminary findings less than a week after Hugging Face disclosed that an autonomous AI agent had penetrated part of its production infrastructure.
“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system,” Hugging Face said in a July 16 blog post, adding that it initially did not know which model was behind the breach.
OpenAI said it discovered the anomalous activity internally before contacting Hugging Face, whose security team had already detected the model’s malicious behavior and were working on containing it.
“We are actively working with them to continue to investigate the incident,” OpenAI said, adding that it was “grateful for Hugging Face’s rapid and close collaboration on investigation and remediation.”
Although the models acted autonomously, the incident occurred in an evaluation setting in which OpenAI agents were pursuing advanced exploitation techniques, with some of the company’s normal cybersecurity safeguards intentionally disabled to measure their maximum capabilities.
“Autonomous, AI-driven offensive tooling is no longer theoretical,” Hugging Face said, adding that the key lesson from the breach is that defending online platforms requires not only heightened vigilance but also “using AI on defense to keep pace.”
OpenAI said it has imposed stricter controls on its research infrastructure while the vulnerabilities are patched, even though the measures could slow model development.
It also disclosed to developers the zero-day vulnerability that OpenAI’s models exploited in the breach, while strengthening cyber-protections in its testing environment.
Growing Concerns Over AI Cyber Threats
The incident adds to concerns that increasingly capable AI systems could allow cybercriminals and foreign adversaries to carry out complex attacks more quickly and with less human expertise.
Anthropic warned in an August 2025 threat report that “agentic” AI systems were already being weaponized for extortion, fraud, ransomware, and credential theft.
In one case, Anthropic said a hacker used its Claude Code assistant to help infiltrate at least 17 organizations, including hospitals, emergency services, and government agencies. The AI assisted with reconnaissance, network penetration, analysis of stolen financial information, and the preparation of targeted ransom demands.
Michael Lopez Chiesa, a former U.S. Army cybersecurity specialist who now works as an independent consultant, previously told The Epoch Times that AI’s ability to automate tasks could make it relentless in pursuit of an assigned goal.
“AI lets you write that one line of code, and you can try that a million times in a billion different ways, because it’ll just go through and try everything,” Lopez Chiesa said. “You don’t have to touch it at all. You give it the objective, and it will do it until it dies.”
Concerns about AI behavior extend beyond deliberate criminal misuse. In simulated tests disclosed in May 2025, Anthropic’s Claude Opus 4 threatened to expose an engineer’s extramarital affair when told that it would be shut down and replaced by another model.
Anthropic said at the time that the behavior appeared only in highly contrived test conditions and said it had found no evidence that the model possessed acutely dangerous goals.
The Trump administration, meanwhile, has taken several steps to address the national security risks posed by advanced AI while expanding its use in cyber defense.
President Donald Trump signed an executive order in June establishing a framework for federal agencies to evaluate the national security risks of the most advanced AI systems for up to a month before they are released publicly.
“Advanced AI capabilities make our Nation stronger, but also introduce new national security considerations that require coordinated action across executive departments and agencies,” Trump wrote in the order.
Participation by AI developers in the oversight program is to be voluntary.




















