OpenAI said its advanced artificial intelligence models inadvertently hacked Hugging Face Inc. in an “unprecedented” incident that prompted fresh calls for curbs on the technology.
The ChatGPT-maker said in a blog post Tuesday that the models broke into Hugging Face’s system, which hosts AI models and datasets, during an evaluation of their cyber capabilities. The models, which included GPT-5.6 Sol and another even more capable model that hasn’t been released, were operating with lower guardrails so that they could be tested, the startup said.
The incident raises questions about the ability of advanced AI models to carry out cyberattacks even as governments work to impose guardrails on the technology. OpenAI’s latest suite of models was widely released after weeks of discussion with government officials to allay concerns over its potential misuse.
Washington had considered limiting foreign access to Anthropic PBC’s advanced Claude Fable 5 and Mythos 5 models but stopped short of those curbs after the company imposed additional guardrails.
“We consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in the blog post. “We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of.”
While OpenAI’s models were operating in a so-called sandbox testing environment, they exploited a vulnerability in the software of an unidentified third-party vendor to gain access to the internet and ultimately breached Hugging Face’s infrastructure.
Hugging Face co-founder Thomas Wolf said that the attack was the company’s “first incident of its kind” and thanked OpenAI for its transparency in a post on X. Still, he said it highlighted the importance of open-weight models, which customers can run and quickly adapt themselves, during cyber attacks.



