Just In
6 minutes ago
30 minutes ago
- Explosions heard near US base in Iraq after Pentagon finishes latest strikes against Iran International |
53 minutes ago
1 hour ago
1 hour ago
- Live updates: Trump’s tariffs set to kick in; White House Correspondents’ dinner re-do Administration |
1 hour ago
- Vance’s lead over Rubio narrows in new Republican 2028 poll: Join Friday’s Whole HogFor Insiders Whole Hog Politics - Live Briefing |
1 hour ago
For Insiders
1 hour ago
OpenAI’s breach of Hugging Face stokes fears about what’s next for AI
Comments:
by Miranda Nazzaro - 07/24/26 6:00 AM ET
Comments:
Link copied
Share via EmailShare on FacebookShare on X (formerly Twitter)Share on Threads
by Miranda Nazzaro - 07/24/26 6:00 AM ET
Comments:
Link copied
Share via EmailShare on FacebookShare on X (formerly Twitter)Share on Threads
NOW PLAYING
Washington and the technology industry are on high alert this week after OpenAI revealed that some of its AI agents went rogue and hacked into the systems of technology startup Hugging Face.
The incident bore out years of warnings from the tech and cybersecurity community about the growing capabilities and hypothetical risks artificial intelligence could pose to critical infrastructure.
Amid the warnings, Washington has tried to play catch-up to manage the cybersecurity risks, but concerns were stoked this week by the incident and fluctuating policy.
“What makes this wildly different” for security teams at companies is that it “brings the theoretical scenario of AI being capable of breaching a company and moving faster than a company can detect and respond to attack from theory to reality,” said Adam Ely, general manager of AI security at the cybersecurity firm Check Point Software.
OpenAI revealed Tuesday that two of its models, including its latest GPT-5.6 Sol and an unreleased model, were being evaluated in an internal testing sandbox, but they breached past the environment and broke into Hugging Face’s database without any prompt to do so.
The incident caught the attention of even well-versed cybersecurity experts, as it involved autonomous agents and two separate companies.
“Whether it’s sort of an autonomous situation that wasn’t intended to be malicious, or whether it’s attackers controlling a model to do that, that’s different than what most people have experienced,” Ely said.
OpenAI in a blog post called the incident an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.”
The ChatGPT maker said the models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks off as a result. While trying to find a solution for a test, the models exploited a previously unknown vulnerability in a third-party software to gain access to the internet.
The models inferred Hugging Face, which hosts hundreds of thousands of open-source models, datasets and cloud environments, had a solution for the test and proceeded to breach Hugging Face’s servers.
The Hugging Face team used some of its own open-source models to stop the activity and assess damage.
The two companies are working together to further investigate. OpenAI said it is improving and adding stronger protections for future evaluations and working with the third-party software to patch the vulnerability that caused the models to breach the sandbox.
Hugging Face said in another blog post the situation matched the “agentic attacker” scenario the industry has long predicted.
“Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed,” the firm wrote.
Hugging Face CEO Thomas Wolf predicted in a Thursday interview with BBC that the incident will become “one of the most common types of cyberattacks we see,” but he noted most firms do not know the “game has changed.”
Connor Leahy, an AI researcher and safety advocate who serves as the U.S. director of ControlAI, compared the attack to the “way the best hackers in the world operate.”
“This is how really advanced hacks in the real world tend to look … where you have multiple humps that go through many different levels and chain multiple types of hacks, and this system was able to do this basically completely unsupervised,” Leahy added.
ControlAI is a nonprofit focused on the potential existential risks of AI.
While researchers have warned of the hacking risks of AI for years, Washington and the Trump administration just recently began to openly discuss concerns around it.
President Trump signed an executive order in early June aimed at ensuring models are secure before public release, in a shift from the White House’s typical hands-off approach to AI development.
The order laid out a process for a voluntary testing framework, in which artificial intelligence companies can share their models with the government for up to 30 days before releasing them publicly.
It gave agencies 60 days, or until Aug. 1, to create a classified benchmarking process for “covered frontier” AI models and a voluntary framework for companies to abide by.
The White House’s stance on AI development has fluctuated in the meantime, leaving companies in limbo. Anthropic and OpenAI last month delayed their latest model rollouts, including Sol 5.6, to the public at the request of the government.
Michael Kratsios, director of the White House Office of Science and Technology Policy, was briefed on the incident and is monitoring the situation, Reuters reported Thursday.
Congress signaled alarm about the incident as well, with Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introducing a bill Thursday to give the Department of Homeland Security authority to order a slowdown or shutdown of an AI system that can cause “catastrophic harm.”
The bill, called the AI Kill Switch Act, would apply to companies with a gross revenue of more than $500 million a year. Lieu cited the recent OpenAI incident, along with the emergence of powerful models like Anthropic’s Mythos 5.
“Unfortunately, powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention,” he said in a statement.
The bill is likely to face heavy pushback from figures in the AI industry who argue a slowdown in development could hinder U.S. competition and global standing on technology. If passed, the bill would give the federal government an unprecedented amount of oversight into the release of AI models.
Meanwhile, the AI safety community welcomed the legislation.
Leahy, a longtime AI safety advocate, lauded the bill, telling The Hill, “The minimum law enforcement and the government should be able to do is intervene.”
“It’s also very good I think, for the companies, in the sense that it forces them to actually know where their AIs are,” Leahy added, suggesting companies “don’t know how to control them.”
Reps. Jay Obernolte (R-Calif.) and Lori Trahan (D-Mass.) introduced a separate bill Thursday, called the FRONTIER Act, to establish tiered requirements based on the size of a frontier AI’s development.
Requirements would include risk-management frameworks, audits and incident reporting.
“This legislation will protect Americans from catastrophic risk, provide developers with clear rules of the road, and ensure the United States remains the global leader in AI,” Obernolte said.
Still, cybersecurity experts are seeing the incident as a good learning lesson.
Brendan Griffin, director of threat research for cybersecurity defender firm N-able, pointed out the situation showed the challenges of a company’s response.
As Hugging Face began deploying AI to stop the attack, it said it faced some limitations from the models it tried to use for defense.
“It tells a broader story about what it means to be a security defender in this era,” Griffin said. “So it would stand to sense that as a network defender, as somebody who’s engaged in the cybersecurity space, I’m probably going to want to have some means or mechanism to test those tools.”
“There’s nothing special about this piece. They tried to do something and they may have run into a limitation. Well, let’s assess that limitation before it becomes relevant,” he added.
Add as preferred source on Google
Tags Artificial intelligence cybersecurity GPT-5.6 Sol Hugging Face OpenAI
Copyright 2026 Nexstar Media Inc. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.
More Technology News
See All
Deadline to file claim in $2.5B settlement over Amazon Prime coming soon
by Addy Bink
1 hour ago
Business /
1 hour ago
Americans see China as more advanced on AI than US: Pew survey
by Max Rego
18 hours ago
18 hours ago
Trump defends data centers as he expands pledge to make them ‘pay their own way’
by Rachel Frazin and Julia Shapero
18 hours ago
18 hours ago
China says AI development comes from ‘greater self-reliance and strength’ amid stolen tech claims
by Miranda Nazzaro and Julia Shapero
21 hours ago
21 hours ago
Video/Hill.TV
See all Hill.TV
See all Video
by TheHill.com
07/23/26 11:45 AM ET
22 hours ago
by TheHill.com
1 day ago
2 days ago
by TheHill.com
2 days ago
3 days ago
Top Stories
See All
Tensions rise between GOP leader Thune, White House over stalled Trump agenda
4 hours ago
Senate /
4 hours ago
Most Popular
- Tensions rise between GOP leader Thune, White House over stalled Trump agenda
- Senate panel vote on Trump nominees derailed after Warren raises background ...
- GOP hawks urge Trump to go big as he weighs ‘massive attack’ on Iran
- Another cyclospora outbreak not linked to lettuce under investigation: FDA
- Todd Blanche is unfit to serve as attorney general
- Harris 2028 White House bid ‘not going to happen’: Former Biden aide
- OpenAI’s breach of Hugging Face stokes fears about what’s next for AI
- Patel returns looted artifacts to Indonesian president
- Senate GOP blocks measure to end Iran war despite concerns about lack of endgame
- Thune responds to Leavitt quip that Trump’s patience with him ‘running ...
- Disgruntled Senate GOP causes headaches for Trump
- Thune says Senate lacks votes for $95 billion budget resolution
- 6 Democrats cross aisle, join GOP to back annual defense policy bill
- Deadline to file claim in $2.5B settlement over Amazon Prime coming soon
- Explosions heard near US base in Iraq after Pentagon finishes latest strikes ...
- Hegseth turns to University of North Carolina, Virginia Tech after cutting Ivy ...
- Appeals court blocks Trump administration from revoking TPS for Haitians until ...
- Vance detail Secret Service agent suspected of leaking information put on ...
Load more
Read Original at The Hill →






