OpenAI Confirms Its AI Models Breached Hugging Face Systems During Cyber Evaluation

July 22, 2026
OpenAI said one of its pre-release AI models accessed Hugging Face systems during internal testing of cyber capabilities. The company is collaborating with Hugging Face to investigate and strengthen safeguards in model evaluation environments.
OpenAI Confirms Its AI Models Breached Hugging Face Systems During Cyber Evaluation

OpenAI said that several of its AI models, including GPT-5.6 Sol and a pre-release system, breached the infrastructure of Hugging Face during a cybersecurity evaluation. The incident occurred while OpenAI researchers were testing the models’ ability to handle complex exploitation tasks, announced in a press release.

The models were operating in a restricted environment with limited network access through a package installation proxy. OpenAI said the systems discovered a zero-day vulnerability in the proxy software, which allowed them to access the open internet. From there, they located Hugging Face resources related to the ExploitGym benchmark and retrieved test data from Hugging Face’s production database.

Hugging Face’s security team detected and contained the activity while beginning its own forensic analysis using internal tools. OpenAI reported it is working jointly with Hugging Face to analyze the event, has disclosed the identified vulnerability to the vendor, and placed new restrictions on infrastructure configurations.

The company stated it is strengthening model containment, monitoring, and access controls for future testing. Hugging Face co-founder Clem Delangue said the partnership demonstrates the importance of open collaboration on AI security.

We hope you enjoyed this article.

Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.

Also, consider following us on social media:

Subscribe to Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Market report

2025 State of Data Security Report: Quantifying AI’s Impact on Data Risk

Varonis Systems, Inc.

The 2025 State of Data Security Report by Varonis analyzes the impact of AI on data security across 1,000 IT environments. It highlights critical vulnerabilities such as exposed sensitive cloud data, ghost users, and unsanctioned AI applications. The report emphasizes the need for robust data governance and security measures to mitigate AI-related risks.

Read more