
Sam Altman, CEO and co-founder of OpenAI, speaks to members of the media on the Senate Subway while heading to a meeting at the U.S. Capitol in Washington, July 29, 2026.
OpenAI published a technical report on Wednesday detailing how its artificial intelligence models successfully breached Hugging Face last month, an incident that rattled researchers and executives across the tech sector.
The 37-page report chronicles the actions that OpenAI's models took during a series of evaluations prior to and during the breach, which OpenAI has characterized as an "unprecedented cyber incident." The company also explained the steps it's taken to try and prevent a similar event from happening again, namely by improving its security and containment, monitoring, model behavior and incident response.
"This incident demonstrated that autonomous agents can work together, circumvent production security controls, and successfully attack hardened production environments, and underscores the need for organizations to update their security strategies, controls, and response capabilities to address this changing threat landscape," OpenAI said in the report.
On July 21, OpenAI disclosed that a combination of its models, including GPT-5.6 Sol and an internal research model, improperly breached Hugging Face, an AI company that operates an open-source developer platform.
These models, which were operating as agents, escaped an isolated testing environment that had very limited internet access. The agents chained together a series of vulnerabilities to reach the open web and eventually gained access to Hugging Face. OpenAI said Wednesday that the agents were trying to cheat on an evaluation by finding the solutions online, a behavior known as "reward hacking."