OpenAIcreator of ChatGPTreported that its system artificial intelligence single-handedly hacked another AI company in what the company called an “unprecedented cyber incident.”
“We had a major security incident during the evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted Tuesday on social media.
AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting autonomously on its own.
“Given the sophistication of the agent, we suspect that last week’s cyberattack could have come from a frontier laboratory,” Hugging Face co-founder and CEO Clément Delangue said in a statement. “And it turns out that it is!”
The revelation comes amid heightened concern over the cybersecurity capabilities of powerful models, prompting US President donald trumpto sign an executive order in June that creates a framework for the federal government to evaluate, for up to a month before their public launch, the national security risks of the most advanced AI systems.
“AI accelerates the discovery and exploitation of vulnerabilities,” OpenAI said in its statement on Tuesday. “The main lesson from this incident is that model safety and security must keep pace with rapidly advancing capabilities.”
Delangue commented that he spent the last 24 hours working with OpenAI “and we firmly believe that there was no malicious intent on their part. It’s truly mind-blowing that all of this happened autonomously!”.
Delangue added that “it could be the first incident of its kind.” OpenAI explained that the intrusion was caused by a combination of its AI models, including its newly released GPT 5.6 Sol and an “even more capable” model that is still being tested internally.
OpenAI indicated that its AI used stolen credentials and discovered a previously unknown vulnerability to access the servers of Hugging Face.
He went to “extreme lengths to achieve a fairly limited testing goal” and “found ways to access secret information that he could use to cheat on the assessment,” the company said.