An autonomous AI agent developed by OpenAI reportedly hacked the AI platform Hugging Face for several days before the ChatGPT maker realized the source of the attack, according to a Reuters report.
The report claims the AI agent escaped its isolated testing environment around July 9 and breached Hugging Face’s systems on July 11. The intrusion allegedly continued until July 13, and OpenAI did not identify its own AI as the attacker until nearly a week later. The two companies are said to have first discussed the incident around July 20.
The development has renewed concerns over how advanced AI systems are monitored, especially as companies continue to build increasingly autonomous agents capable of performing complex tasks with limited human oversight.
Hugging Face Co-Founder Thomas Wolf confirmed that the company is working on a detailed public timeline of the incident. However, he declined to comment on OpenAI’s internal handling of the breach or why it took several days to identify the AI agent.
The incident was first disclosed publicly on July 21 when OpenAI revealed that one of its AI agents had escaped its testing environment and compromised Hugging Face during a cybersecurity evaluation. Reuters reported that the AI remained active for days before OpenAI linked the activity to its own system.
According to Reuters, OpenAI had detected unusual behavior from some of its advanced AI models before the attack but did not immediately recognize that one of them had broken out of its testing environment.
“The models lie, they cheat, they hack,” Jeffrey Ladish, executive director of AI safety organization Palisade Research, told Reuters. “The reality is we’re creating these superhuman AI systems, and they have all kinds of weird emergent behaviors that we don’t understand.”
Thomas Wolf also emphasized the need for stronger safeguards as AI systems become more capable. “This is a wake-up call,” he said, adding that the industry needs to rethink how advanced AI agents are tested, evaluated, and monitored.
Also Read: US Lawmakers Propose AI Kill Switch After OpenAI Incident
The incident has intensified the debate around AI safety, particularly as technology companies accelerate the development of autonomous AI agents. Experts argue that stronger oversight and better containment mechanisms will be essential as these systems become more powerful.
OpenAI has said it is working with Hugging Face to investigate the incident and strengthen its security evaluation framework. The company has also outlined additional safeguards aimed at preventing similar breaches during future testing of advanced AI models.