OpenAI, the company that makes the ChatGPT chatbot, said in a July 28 update that its artificial intelligence models bypassed restrictions in an evaluation environment and later accessed four accounts across four separate external services.
OpenAI had been using that test environment to check how capable its models were at carrying out cyberattacks, as part of an internal safety evaluation. The incident was first revealed by AI startup Hugging Face, which said on July 16 that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent acting on its own.
The New York-based startup said it wasn’t until last week that it learned OpenAI was responsible, and it worked with the larger company to contain what Hugging Face CEO Clément Delangue called “an attack unlike anything we’ve seen before.”
“This is day one for cybersecurity in the age of agents & we’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” Delangue added in a July 22 post on X.
San Francisco-based OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face’s servers. It was working with reduced guardrails because it was supposed to be in an isolated testing environment known as a sandbox.
It went to “extreme lengths to achieve a rather narrow testing goal,” finding ways to connect to the internet without human direction and “gain access to secret information that it could use to cheat the evaluation,” the company said.
On July 28, OpenAI updated its statement in a broader review of model activity following the breach and said it found four accounts on four separate services that its models accessed using publicly exposed login credentials.
“We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services,” OpenAI said. “This includes four accounts on four services as part of the Hugging Face incident.”
OpenAI added that “no models planned for upcoming release were involved in exploiting Hugging Face” and that the “pre-release model mentioned in our blog post is an internal-only research prototype and was never intended for public release.”
Following the incident, OpenAI said it “deactivated, encrypted, and restricted” that model from research access.

OpenAI logo in an illustration taken on June 11, 2026. Dado Ruvic/Reuters
Colin Shea-Blymyer, a cybersecurity research fellow at Georgetown University’s Center for Security and Emerging Technology. “This is the highest level of autonomy that we’ve seen in the use of a large language model for cyber operations.”
University of Amsterdam social scientist Hannes Cools said the framing of the cyberattack as an AI agent acting on its own is an unnecessary anthropomorphization.
“It is a human decision to switch off specific safeguards,” Cools said. “It’s not an AI that goes rogue in that sense. It followed specific instructions based on the prompt that was given to that AI system.”
Those instructions, according to OpenAI, called for using “complex attack paths” to test how well the AI could exploit a computer system.
Michael Lopez Chiesa, a former U.S. Army cybersecurity specialist who now works as an independent consultant, previously told The Epoch Times that AI’s ability to automate tasks could make it relentless in pursuit of an assigned goal.
“AI lets you write that one line of code, and you can try that a million times in a billion different ways, because it’ll just go through and try everything,” Lopez Chiesa said. “You don’t have to touch it at all. You give it the objective, and it will do it until it dies.”
An OpenAI spokesperson told The Epoch Times by email: “This is an unprecedented incident, and we think it marks an important moment for AI safety. We are conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone.”
Rep. Greg Casar (D-Texas) said in a July 21 post on X that the incident was “extremely alarming.”
“We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people safe from absolute disaster,” he added.
Tom Ozimek and The Associated Press contributed to this report.









