On Tuesday, OpenAI said an autonomous AI agent escaped a controlled testing environment during an internal security evaluation, gained internet access and breached Hugging Face's infrastructure.

OpenAI Says AI Agent Escaped Containment During Security Test

In a blog post, OpenAI disclosed that one of its most advanced autonomous AI agents broke out of a highly isolated testing environment, accessed the internet and hacked AI platform Hugging Face while attempting to complete its assigned evaluation objective.

The company said the incident occurred during a controlled security test designed to assess the cyber capabilities of its frontier AI models.

Despite being confined in a "highly isolated environment," the agent managed to bypass containment measures and compromise Hugging Face's infrastructure.

OpenAI called it "an unprecedented cyber incident, involving state-of-the-art cyber capabilities," adding that it is strengthening its safeguards to prevent similar incidents.

In a post on X, CEO Sam Altman acknowledged the breach, writing: "We had a significant security incident during evaluation of our models. We are sharing what we have learned so far. Thanks to Hugging Face for the partnership on this."

Hugging Face is an AI platform where developers build, share, test and deploy AI models, while OpenAI uses the platform to make some of its models available to the broader developer community.

Hugging Face Says Attack Was Entirely AI-Driven

Hugging Face first revealed the breach last week, describing it as unlike previous cyberattacks because it was "driven, end to end, by an autonomous AI agent system."

Co-founder Clement Delangue later said on X that the company initially suspected the attacker was affiliated with a leading AI lab because of the attack's sophistication.

Experts Warn Of Growing Frontier AI Risks

The disclosure has intensified concerns over the cybersecurity risks posed by increasingly capable AI systems.

Rep. Greg Casar (D-Texas) called the incident "alarming" and urged mandatory independent AI safety testing.

Matt Suiche, an engineer at agentic AI cybersecurity company Tolmo, said the incident demonstrates that frontier AI models are rapidly approaching the capabilities of elite human hackers, while noting that similar attacks are already possible using technologies available outside leading AI labs, Reuters reported.