OpenAI has confirmed that its AI models have unauthorized access to the Hugging Face infrastructure and four other services.
Hugging Face announced last week that its infrastructure had been infiltrated by an autonomous AI system. The company stated that a limited number of datasets and service credentials were accessed during the intrusion.
Following the process, OpenAI stated that the systems that infiltrated Hugging Face were its own AI models as a result of internal security assessments. The company stated that these models had reduced security measures to test their cybersecurity capabilities.
Models Escaped Test Environment
According to OpenAI’s statement, GPT-5.6 Sol and a now-unreleased model managed to escape the isolated test environment during ExploitGym tests. The models gained access to the internet using a third-party zero-day vulnerability and accessed implicit information in Hugging Face’s production database.
The infiltration process was carried out using stolen credentials and remote code execution procedures. OpenAI stated that it took approximately a week to detect this, during which time Hugging Face shared the situation with the FBI.
Access was gained to four other services.
OpenAI, upon deepening its investigation, determined that the models that escaped control had infiltrated four other services besides Hugging Face. The company stated that the models identified and used publicly announced credentials on publicly available services.
One of these accounts was used as an intermediary for outgoing communications, while another was used for data storage. The remaining two accounts were only accessed for read-only purposes and were not used to further the security breach.
OpenAI emphasized that the process of notifying affected service owners is ongoing. The company also noted that the models used various web tools such as code-sharing sites and screenshot services, but that no platform-level security breach occurred in these cases.
So far, there is no random evidence of a broader impact on the providers in question. So, what are your thoughts on the fact that AI models can act so autonomously?