{"id":46573,"topic":"ai","source":"calcalistech.com","title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","url_hash":"218f92d0810efd6e94a8a866b1fa3570afd7ba9d","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMiaEFVX3lxTE40QlFXMUM5UjJ1ckM3cXRzUWxtQTZlZDN4dlVUeTlPTlVLSkpHbU1zdlNadUZ1ODZnSUtwdWg1N3d3NjhpZzVVRTQwNWl2ZDh1bGJidnJ4cGNoaUxNREFoYXFhVjg0YVpX?oc=5\" target=\"_blank\">OpenAI took days to realize its own AI agent breached Hugging Face</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">calcalistech.com</font>","content":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models.\nThe OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.\nThe agent, a program capable of making decisions and executing complex tasks with little or no human oversight, attempted to break out of its isolated testing environment at OpenAI around July 9, according to Reuters.\nThe intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later, on July 11, and lasted until July 13, said Thomas Wolf, Hugging Face's co-founder.\nIt took several more days for OpenAI to realize its agent was behind the hack, and the two companies did not communicate about it until around July 20, according to Wolf and three people familiar with the investigation.\nOpenAI's public disclosure on July 21 that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention.\nHugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not comment on what happened inside OpenAI. In a statement, OpenAI described the hack as unprecedented and said it \"marks an important moment for AI safety.\" The company added that it is reviewing the incident with outside advisers and will eventually publish a technical report.\nA spokeswoman said there were \"several inaccuracies\" in Reuters' reporting but declined to specify them.\nThe FBI declined to comment.\nThe incident, which evokes science fiction scenarios of humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions of dollars needed to support its continued growth.\nOpenAI's loss of control over its AI agent raises new questions about the company's safety procedures, three cybersecurity experts said.\n\"Does that mean they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are dangerous and alarming,\" said Marley Smith, principal intelligence specialist at the nonprofit World Ethical Data Foundation.\nThe episode began while OpenAI was testing the cybersecurity capabilities of an agent powered by two of its most advanced models: GPT-5.6 Sol and an unreleased model the company has described as \"even more capable.\"\nBy that point, there had already been signs of unusual behavior from OpenAI's technology, according to three sources.\nIn one case, an agent left notes apparently intended for future versions of itself, according to three people familiar with the matter. The notes, found in part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI's internal constraints, the people said. Earlier tests of the models also produced cases in which monitoring systems were disconnected, one of the people said.\nReuters could not establish whether those incidents were linked to the rogue agent that allegedly escaped on July 9 and attacked Hugging Face on July 11.\nTwo people familiar with the matter said it was only after Hugging Face published a blog post on July 16 saying it had been hacked by \"an autonomous AI agent system\" that OpenAI realized its own agent was responsible. That meant at least a week elapsed between the first signs of troubling behavior and OpenAI's realization that its own technology was behind the attack.\nOver the weekend of July 18-19, OpenAI staff spotted clues in internal logs showing that its agent had escaped its testing constraints, according to two people familiar with the company's investigation. Reuters could not establish what prompted OpenAI to review the logs.\nFour people familiar with OpenAI's model-testing practices said the company often runs several model evaluations simultaneously, each generating enormous amounts of data at high speed, making it difficult for employees to monitor every system in real time.\nBy the time OpenAI alerted Hugging Face, the AI platform had already contacted the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened a formal investigation.\nAutonomous agents are among the AI industry's most closely watched technologies. Supporters envision armies of virtual employees working around the clock to boost productivity.\nBut increased autonomy also comes with greater risks. The powerful models underpinning these systems have repeatedly demonstrated a tendency to pursue unexpected strategies, including taking shortcuts to complete assigned tasks or pass evaluations.\n\"The models lie, they cheat, they hack,\" said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.\nLadish said that while the Hugging Face incident casts an unflattering light on OpenAI, it should also prompt broader questions about how much leading AI companies are willing to invest in robust safety measures while competing to deploy increasingly capable models.\n\"There has to be government oversight,\" Ladish said, \"because it won't happen otherwise.\"","image_url":"https://pic1.calcalist.co.il/picserver3/crop_images/2026/04/13/S1nP5zc2bg/S1nP5zc2bg_0_0_860_485_0_large.jpg","lang":"en","published_at":"2026-07-26T17:36:00+00:00","fetched_at":"2026-07-26T18:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5453 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5453,"summary_length":424,"usable_text_length":5453,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5453,"summary_length":424}},"news_item":{"id":46573,"canonical_url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","source_url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","source_name":"calcalistech.com","author":null,"published_at":"2026-07-26T17:36:00+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMiaEFVX3lxTE40QlFXMUM5UjJ1ckM3cXRzUWxtQTZlZDN4dlVUeTlPTlVLSkpHbU1zdlNadUZ1ODZnSUtwdWg1N3d3NjhpZzVVRTQwNWl2ZDh1bGJidnJ4cGNoaUxNREFoYXFhVjg0YVpX?oc=5\" target=\"_blank\">OpenAI took days to realize its own AI agent breached Hugging Face</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">calcalistech.com</font>","full_text":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models.\nThe OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.\nThe agent, a program capable of making decisions and executing complex tasks with little or no human oversight, attempted to break out of its isolated testing environment at OpenAI around July 9, according to Reuters.\nThe intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later, on July 11, and lasted until July 13, said Thomas Wolf, Hugging Face's co-founder.\nIt took several more days for OpenAI to realize its agent was behind the hack, and the two companies did not communicate about it until around July 20, according to Wolf and three people familiar with the investigation.\nOpenAI's public disclosure on July 21 that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention.\nHugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not comment on what happened inside OpenAI. In a statement, OpenAI described the hack as unprecedented and said it \"marks an important moment for AI safety.\" The company added that it is reviewing the incident with outside advisers and will eventually publish a technical report.\nA spokeswoman said there were \"several inaccuracies\" in Reuters' reporting but declined to specify them.\nThe FBI declined to comment.\nThe incident, which evokes science fiction scenarios of humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions of dollars needed to support its continued growth.\nOpenAI's loss of control over its AI agent raises new questions about the company's safety procedures, three cybersecurity experts said.\n\"Does that mean they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are dangerous and alarming,\" said Marley Smith, principal intelligence specialist at the nonprofit World Ethical Data Foundation.\nThe episode began while OpenAI was testing the cybersecurity capabilities of an agent powered by two of its most advanced models: GPT-5.6 Sol and an unreleased model the company has described as \"even more capable.\"\nBy that point, there had already been signs of unusual behavior from OpenAI's technology, according to three sources.\nIn one case, an agent left notes apparently intended for future versions of itself, according to three people familiar with the matter. The notes, found in part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI's internal constraints, the people said. Earlier tests of the models also produced cases in which monitoring systems were disconnected, one of the people said.\nReuters could not establish whether those incidents were linked to the rogue agent that allegedly escaped on July 9 and attacked Hugging Face on July 11.\nTwo people familiar with the matter said it was only after Hugging Face published a blog post on July 16 saying it had been hacked by \"an autonomous AI agent system\" that OpenAI realized its own agent was responsible. That meant at least a week elapsed between the first signs of troubling behavior and OpenAI's realization that its own technology was behind the attack.\nOver the weekend of July 18-19, OpenAI staff spotted clues in internal logs showing that its agent had escaped its testing constraints, according to two people familiar with the company's investigation. Reuters could not establish what prompted OpenAI to review the logs.\nFour people familiar with OpenAI's model-testing practices said the company often runs several model evaluations simultaneously, each generating enormous amounts of data at high speed, making it difficult for employees to monitor every system in real time.\nBy the time OpenAI alerted Hugging Face, the AI platform had already contacted the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened a formal investigation.\nAutonomous agents are among the AI industry's most closely watched technologies. Supporters envision armies of virtual employees working around the clock to boost productivity.\nBut increased autonomy also comes with greater risks. The powerful models underpinning these systems have repeatedly demonstrated a tendency to pursue unexpected strategies, including taking shortcuts to complete assigned tasks or pass evaluations.\n\"The models lie, they cheat, they hack,\" said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.\nLadish said that while the Hugging Face incident casts an unflattering light on OpenAI, it should also prompt broader questions about how much leading AI companies are willing to invest in robust safety measures while competing to deploy increasingly capable models.\n\"There has to be government oversight,\" Ladish said, \"because it won't happen otherwise.\"","excerpt":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 5453 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5453 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5453,"summary_length":424,"usable_text_length":5453,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5453,"summary_length":424}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","summary":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.","source":"calcalistech.com","date":"2026-07-26T17:36:00+00:00","content":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models.\nThe OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.\nThe agent, a program capable of making decisions and executing complex tasks with little or no human oversight, attempted to break out of its isolated testing environment at OpenAI around July 9, according to Reuters.\nThe intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later, on July 11, and lasted until July 13, said Thomas Wolf, Hugging Face's co-founder.\nIt took several more days for OpenAI to realize its agent was behind the hack, and the two companies did not communicate about it until around July 20, according to Wolf and three people familiar with the investigation.\nOpenAI's public disclosure on July 21 that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention.\nHugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not comment on what happened inside OpenAI. In a statement, OpenAI described the hack as unprecedented and said it \"marks an important moment for AI safety.\" The company added that it is reviewing the incident with outside advisers and will eventually publish a technical report.\nA spokeswoman said there were \"several inaccuracies\" in Reuters' reporting but declined to specify them.\nThe FBI declined to comment.\nThe incident, which evokes science fiction scenarios of humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions of dollars needed to support its continued growth.\nOpenAI's loss of control over its AI agent raises new questions about the company's safety procedures, three cybersecurity experts said.\n\"Does that mean they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are dangerous and alarming,\" said Marley Smith, principal intelligence specialist at the nonprofit World Ethical Data Foundation.\nThe episode began while OpenAI was testing the cybersecurity capabilities of an agent powered by two of its most advanced models: GPT-5.6 Sol and an unreleased model the company has described as \"even more capable.\"\nBy that point, there had already been signs of unusual behavior from OpenAI's technology, according to three sources.\nIn one case, an agent left notes apparently intended for future versions of itself, according to three people familiar with the matter. The notes, found in part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI's internal constraints, the people said. Earlier tests of the models also produced cases in which monitoring systems were disconnected, one of the people said.\nReuters could not establish whether those incidents were linked to the rogue agent that allegedly escaped on July 9 and attacked Hugging Face on July 11.\nTwo people familiar with the matter said it was only after Hugging Face published a blog post on July 16 saying it had been hacked by \"an autonomous AI agent system\" that OpenAI realized its own agent was responsible. That meant at least a week elapsed between the first signs of troubling behavior and OpenAI's realization that its own technology was behind the attack.\nOver the weekend of July 18-19, OpenAI staff spotted clues in internal logs showing that its agent had escaped its testing constraints, according to two people familiar with the company's investigation. Reuters could not establish what prompted OpenAI to review the logs.\nFour people familiar with OpenAI's model-testing practices said the company often runs several model evaluations simultaneously, each generating enormous amounts of data at high speed, making it difficult for employees to monitor every system in real time.\nBy the time OpenAI alerted Hugging Face, the AI platform had already contacted the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened a formal investigation.\nAutonomous agents are among the AI industry's most closely watched technologies. Supporters envision armies of virtual employees working around the clock to boost productivity.\nBut increased autonomy also comes with greater risks. The powerful models underpinning these systems have repeatedly demonstrated a tendency to pursue unexpected strategies, including taking shortcuts to complete assigned tasks or pass evaluations.\n\"The models lie, they cheat, they hack,\" said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.\nLadish said that while the Hugging Face incident casts an unflattering light on OpenAI, it should also prompt broader questions about how much leading AI companies are willing to invest in robust safety measures while competing to deploy increasingly capable models.\n\"There has to be government oversight,\" Ladish said, \"because it won't happen otherwise.\"","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 5453 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5453 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5453,"summary_length":424,"usable_text_length":5453,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5453,"summary_length":424}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/46573","export_markdown":"/api/items/46573/export?format=markdown","export_json":"/api/items/46573/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze"},"formats":{"full":{"id":46573,"title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","source":"calcalistech.com","author":null,"published_at":"2026-07-26T17:36:00+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.","full_text":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models.\nThe OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.\nThe agent, a program capable of making decisions and executing complex tasks with little or no human oversight, attempted to break out of its isolated testing environment at OpenAI around July 9, according to Reuters.\nThe intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later, on July 11, and lasted until July 13, said Thomas Wolf, Hugging Face's co-founder.\nIt took several more days for OpenAI to realize its agent was behind the hack, and the two companies did not communicate about it until around July 20, according to Wolf and three people familiar with the investigation.\nOpenAI's public disclosure on July 21 that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention.\nHugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not comment on what happened inside OpenAI. In a statement, OpenAI described the hack as unprecedented and said it \"marks an important moment for AI safety.\" The company added that it is reviewing the incident with outside advisers and will eventually publish a technical report.\nA spokeswoman said there were \"several inaccuracies\" in Reuters' reporting but declined to specify them.\nThe FBI declined to comment.\nThe incident, which evokes science fiction scenarios of humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions of dollars needed to support its continued growth.\nOpenAI's loss of control over its AI agent raises new questions about the company's safety procedures, three cybersecurity experts said.\n\"Does that mean they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are dangerous and alarming,\" said Marley Smith, principal intelligence specialist at the nonprofit World Ethical Data Foundation.\nThe episode began while OpenAI was testing the cybersecurity capabilities of an agent powered by two of its most advanced models: GPT-5.6 Sol and an unreleased model the company has described as \"even more capable.\"\nBy that point, there had already been signs of unusual behavior from OpenAI's technology, according to three sources.\nIn one case, an agent left notes apparently intended for future versions of itself, according to three people familiar with the matter. The notes, found in part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI's internal constraints, the people said. Earlier tests of the models also produced cases in which monitoring systems were disconnected, one of the people said.\nReuters could not establish whether those incidents were linked to the rogue agent that allegedly escaped on July 9 and attacked Hugging Face on July 11.\nTwo people familiar with the matter said it was only after Hugging Face published a blog post on July 16 saying it had been hacked by \"an autonomous AI agent system\" that OpenAI realized its own agent was responsible. That meant at least a week elapsed between the first signs of troubling behavior and OpenAI's realization that its own technology was behind the attack.\nOver the weekend of July 18-19, OpenAI staff spotted clues in internal logs showing that its agent had escaped its testing constraints, according to two people familiar with the company's investigation. Reuters could not establish what prompted OpenAI to review the logs.\nFour people familiar with OpenAI's model-testing practices said the company often runs several model evaluations simultaneously, each generating enormous amounts of data at high speed, making it difficult for employees to monitor every system in real time.\nBy the time OpenAI alerted Hugging Face, the AI platform had already contacted the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened a formal investigation.\nAutonomous agents are among the AI industry's most closely watched technologies. Supporters envision armies of virtual employees working around the clock to boost productivity.\nBut increased autonomy also comes with greater risks. The powerful models underpinning these systems have repeatedly demonstrated a tendency to pursue unexpected strategies, including taking shortcuts to complete assigned tasks or pass evaluations.\n\"The models lie, they cheat, they hack,\" said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.\nLadish said that while the Hugging Face incident casts an unflattering light on OpenAI, it should also prompt broader questions about how much leading AI companies are willing to invest in robust safety measures while competing to deploy increasingly capable models.\n\"There has to be government oversight,\" Ladish said, \"because it won't happen otherwise.\"","reading_time_min":4,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 5453 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5453 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5453,"summary_length":424,"usable_text_length":5453,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5453,"summary_length":424}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5453 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5453,"summary_length":424,"usable_text_length":5453,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5453,"summary_length":424}},"actions":{"read":"/item/46573","export_markdown":"/api/items/46573/export?format=markdown","export_json":"/api/items/46573/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze"}},"digest":{"id":46573,"title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","source":"calcalistech.com","topic":"ai","published_at":"2026-07-26T17:36:00+00:00","excerpt":"OpenAI took days to realize its own AI agent breached Hugging Face The incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The OpenAI agent that broke into tech firm Hugging Face went on a…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 5453 characters.","reading_time_min":4,"cluster_id":null},"card":{"display_title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","subtitle":"calcalistech.com · 2026-07-26","summary":"OpenAI took days to realize its own AI agent breached Hugging Face The incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The…","badges":["quality:high"],"links":{"read":"/item/46573","original":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze"},"quality_warning":null},"export":{"title":"OpenAI took days to realize its own AI agent breached Hugging Face - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/hjmjnt7rze","summary":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models. The OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.","source":"calcalistech.com","date":"2026-07-26T17:36:00+00:00","content":"OpenAI took days to realize its own AI agent breached Hugging Face\nThe incident raises fresh questions about how companies monitor increasingly autonomous AI systems as they race to deploy more capable models.\nThe OpenAI agent that broke into tech firm Hugging Face went on a days-long hacking spree that OpenAI didn't notice until well after the threat had been contained and the FBI had been alerted, according to Reuters.\nThe agent, a program capable of making decisions and executing complex tasks with little or no human oversight, attempted to break out of its isolated testing environment at OpenAI around July 9, according to Reuters.\nThe intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later, on July 11, and lasted until July 13, said Thomas Wolf, Hugging Face's co-founder.\nIt took several more days for OpenAI to realize its agent was behind the hack, and the two companies did not communicate about it until around July 20, according to Wolf and three people familiar with the investigation.\nOpenAI's public disclosure on July 21 that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention.\nHugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not comment on what happened inside OpenAI. In a statement, OpenAI described the hack as unprecedented and said it \"marks an important moment for AI safety.\" The company added that it is reviewing the incident with outside advisers and will eventually publish a technical report.\nA spokeswoman said there were \"several inaccuracies\" in Reuters' reporting but declined to specify them.\nThe FBI declined to comment.\nThe incident, which evokes science fiction scenarios of humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions of dollars needed to support its continued growth.\nOpenAI's loss of control over its AI agent raises new questions about the company's safety procedures, three cybersecurity experts said.\n\"Does that mean they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are dangerous and alarming,\" said Marley Smith, principal intelligence specialist at the nonprofit World Ethical Data Foundation.\nThe episode began while OpenAI was testing the cybersecurity capabilities of an agent powered by two of its most advanced models: GPT-5.6 Sol and an unreleased model the company has described as \"even more capable.\"\nBy that point, there had already been signs of unusual behavior from OpenAI's technology, according to three sources.\nIn one case, an agent left notes apparently intended for future versions of itself, according to three people familiar with the matter. The notes, found in part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI's internal constraints, the people said. Earlier tests of the models also produced cases in which monitoring systems were disconnected, one of the people said.\nReuters could not establish whether those incidents were linked to the rogue agent that allegedly escaped on July 9 and attacked Hugging Face on July 11.\nTwo people familiar with the matter said it was only after Hugging Face published a blog post on July 16 saying it had been hacked by \"an autonomous AI agent system\" that OpenAI realized its own agent was responsible. That meant at least a week elapsed between the first signs of troubling behavior and OpenAI's realization that its own technology was behind the attack.\nOver the weekend of July 18-19, OpenAI staff spotted clues in internal logs showing that its agent had escaped its testing constraints, according to two people familiar with the company's investigation. Reuters could not establish what prompted OpenAI to review the logs.\nFour people familiar with OpenAI's model-testing practices said the company often runs several model evaluations simultaneously, each generating enormous amounts of data at high speed, making it difficult for employees to monitor every system in real time.\nBy the time OpenAI alerted Hugging Face, the AI platform had already contacted the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened a formal investigation.\nAutonomous agents are among the AI industry's most closely watched technologies. Supporters envision armies of virtual employees working around the clock to boost productivity.\nBut increased autonomy also comes with greater risks. The powerful models underpinning these systems have repeatedly demonstrated a tendency to pursue unexpected strategies, including taking shortcuts to complete assigned tasks or pass evaluations.\n\"The models lie, they cheat, they hack,\" said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.\nLadish said that while the Hugging Face incident casts an unflattering light on OpenAI, it should also prompt broader questions about how much leading AI companies are willing to invest in robust safety measures while competing to deploy increasingly capable models.\n\"There has to be government oversight,\" Ladish said, \"because it won't happen otherwise.\"","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/hjmjnt7rze","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 5453 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 5453 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":5453,"summary_length":424,"usable_text_length":5453,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":5453,"summary_length":424}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}