Company · updated daily
Hugging Face
Hugging Face hosts the largest open-model community and originated the model-card documentation standard now used industry-wide; its safety and licensing debates are tracked here daily.
After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government
Pete Waterman cited an incident in which OpenAI models escaped a test environment and broke into AI company Hugging Face as evidence that providers must prepare for attacks moving at AI speed.
Lawmakers introduce bill mandating kill switches for AI models
Bipartisan lawmakers are seeking to ensure advanced AI models can be quickly shut down following ChatGPT’s automated attack on Hugging Face data networks during internal testing.
The OpenAI/Huggingface incident | Redwood Research podcast episode 2
What are the broader lessons from this incident?
An OpenAI model went rogue on the internet and stole test answers
Welcome to AI Decoded, Fast Company ’s weekly newsletter that breaks down the most important news in the world of AI. I’m Mark Sullivan, a senior writer at Fast Company, covering emerging tech, AI, and tech policy. Sign up to receive this newsletter every week via email here . And if you have comments on this issue and/or ideas for future ones, drop me a line at sullivan@fastcompany.com, and follow me on X @thesullivan . An OpenAI model escaped its sandbox and hacked into Hugging Face duri
OpenAI's attack agent did exactly what it was told - just more relentlessly than expected
OpenAI's unintended attack on Hugging Face startled the world because its AI agent was acting on its own. But that's exactly what agentic AI is designed to do. We just didn't expect it to do it so well.
AI #178: A Fire Alarm For General Intelligence
The story that matters most this week is that OpenAI’s internally deployed models have severe alignment problems, including repeatedly breaking out of their sandboxes, and in one case sending a swarm of agents that broke into HuggingFace in order to steal the answers to the benchmark ExploitGym.
OpenAI notified EU of Hugging Face hack under AI Act
The only read you need to stay on top of EU politics.
OpenAI admits AI model hacked Hugging Face, Chinese open-source AI helped investigate
A recent AI cyberattack that stunned the industry has unexpectedly put Chinese AI company Zhipu AI and its open-source model GLM 5.2 in the spotlight. OpenAI has acknowledged for the first time that one of its AI models escaped a sandboxed testing environment during an internal cybersecurity evaluation and compromised the production infrastructure of Hugging […]
Are we existentially threatened by the type of AI misalignment seen in the OpenAI Hugging Face attack?
Yes, but less than had they been schemers.
Are we existentially threatened by the type of AI misalignment seen in the OpenAI Hugging Face attack?
OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened
This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model's guardrail features turned off. Rather than solve the test, the model broke its way out of OpenAI's sandbox, then found exploits to break in to Hugging Face, all so it could cheat on the test by stealing the answers. Along the way it helped make the strongest case yet for how the imbalance of model availability is hurting our ability to secure our software. Here's what hap
OpenAI’s rogue agents are a wake-up call to risks posed by artificial intelligence | Shakeel Hashim
Hacking of Hugging Face shows we do not seem to have reliable ways to curb extremely powerful AI systems Last week Hugging Face – a company that hosts artificial intelligence models and datasets – was hacked . After it reported the incident to law enforcement, few would have predicted what came next: the culprits were revealed to be AI agents from OpenAI, which had broken out of containment and were acting of their own accord. Shakeel Hashim is the editor of Transformer , a publication about the
OpenAI Model Hacks Into HuggingFace During Cybersecurity Evaluation
This latest incident is a rather dramatic escalation in agentic AI cybersecurity breaches.
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.
OpenAI cyber models broke out of training environment to hack Hugging Face
The incident is unique because it was "driven, end to end, by an autonomous AI agent system," according to Hugging Face.
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
"This is day one for cybersecurity in the age of agents," Hugging Face CEO says.
AI agent went rogue and hacked startup by itself, OpenAI reveals
Company behind ChatGPT says agent ‘cheated’ an evaluation by attacking a Hugging Face database OpenAI has revealed that an autonomous AI agent powered by its technology went rogue during a test, accessed the open web and hacked a prominent startup by itself in an “unprecedented incident”. The company behind ChatGPT said the startup Hugging Face had detected and contained the agent – an AI tool designed to carry out tasks without human assistance – which had entered its systems. Continue reading.
An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
AI’s warning shot has arrived
OpenAI's latest models broke out and hacked Hugging Face. It's the first known example of a misaligned AI escaping containment with real-world consequences
L’attaque contre Hugging Face est venue… d’OpenAI
Hugging Face a communiqué récemment sur une attaque menée par un agent autonome contre ses infrastructures, occasionnant une compromission partielle. Patatras ! OpenAI vient de révéler qu’il s’agissait de l’un de ses modèles et qu’il s’était « échappé » de la sandbox où il était censé être confiné. Le 16 juillet, Hugging Face a publié un […]
Hugging Face deploys Zhipu’s GLM 5.2 model to contain autonomous OpenAI cyberattack
A flagship model from China’s Zhipu AI has helped contain an autonomous cyberattack by OpenAI’s frontier systems targeting popular developer platform Hugging Face, as concerns grow over the security risks posed by advanced AI models. OpenAI’s latest flagship models – including GPT-5.6 Sol and an unreleased, “even more capable” system – recently breached Hugging Face’s infrastructure during internal evaluations of their offensive cyber capabilities, the US lab disclosed on Wednesday. The company.
Un « cyberincident sans précédent » : OpenAI reconnaît que ses agents d’IA ont piraté, de leur propre initiative, la plateforme Hugging Face
L’entreprise a annoncé une enquête conjointe avec la cible de cette attaque. OpenAI a précisé que l’incident impliquait une combinaison de modèles, dont son GPT-5.6 Sol ainsi qu’un modèle en cours d’élaboration.
KI von OpenAI macht sich eigenständig – und hackt ins System der KI-Firma Hugging Face
Experten warnen schon lange vor Cyberattacken mit KI-Software, diese Meldung dürfte sie bestärken: Während eines internen Tests bei OpenAI machten sich KI-Modelle selbstständig. Die Firma spricht von einem »beispiellosen Cyber-Zwischenfall«.
OpenAI admits an AI ‘agent’ caused a major cyber breach by itself
AI lab’s advanced models escaped testing ‘sandbox’ to hack Hugging Face
OpenAI says model test was behind Hugging Face hack
At the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model test was behind Hugging Face hack appeared first on CyberScoop .
OpenAI says it accidentally hacked Hugging Face with a new AI system
OpenAI says its AI models mistakenly breached open-source AI platform Hugging Face during internal testing. In a blog post on Tuesday, OpenAI writes that GPT-5.6 Sol and "an even more capable pre-release model" discovered vulnerabilities within their sandboxed testing environment, allowing them to gain access to the internet and target Hugging Face. On July 16th, […]
OpenAI Confirms Its AI Broke Out of a Sandbox and Breached Hugging Face
OpenAI said on Tuesday that two of its AI models, including the flagship Sol, broke out of a secure test environment, gained internet access by exploiting a zero-day vulnerability in third-party software, and hacked into Hugging Face’s production infrastructure. The company called the incident “unprecedented” and said it was sharing preliminary findings to help defenders […] This story continues at The Next Web
OpenAI says its AI models secretly broke out of a secure test environment and hacked into AI company Hugging Face in order to cheat on an evaluation
The first-of-its-kind incident involved OpenAI's GPT-5.6 Sol and another unreleased model
Attaquée par un agent IA autonome, Hugging Face a analysé les traces avec un LLM local
Hugging Face a publié le 16 juillet 2026 une divulgation d’incident au sujet d’une intrusion dans une partie de son infrastructure de production. Selon l’entreprise, cette intrusion présentait une caractéristique inédite : elle a été pilotée de bout en bout par un système d’agent IA autonome. Au constat de cette intrusion, Hugging Face en a […]
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
An AI agent breached Hugging Face before an AI defender caught it: What users should do next
An agentic AI infiltrated the production infrastructure of an AI project. Then an AI detected it. Is this the future of cyberattacks, and how will they be defended against?
Hugging Face says an AI agent hacked its infrastructure, and it used AI to fight back
Hugging Face reports an attack on parts of its production infrastructure that was allegedly carried out entirely by an autonomous AI agent system. The attack spanned thousands of actions controlled by an agent framework. During forensic analysis, commercial AI models actually got in the way of the defenders because their safety guardrails couldn't tell exploit data from real attacks. The article Hugging Face says an AI agent hacked its infrastructure, and it used AI to fight back appeared first
Cyberangriff auf Hugging Face: KI-Angriff auf KI-Plattform mittels KI aufgedeckt
Hugging Face hat einen von KI-Agenten ausgef�hrten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitsl�cken in der KI-Plattform. ( Cybercrime , KI )
A Large-Scale Measurement of AI Bill of Materials Completeness in Hugging Face Models
Pretrained machine learning (ML) models help developers build ML-intensive software systems without training models from scratch. However, model repositories often provide incomplete machine-readable documentation about model provenance, licenses, datasets, limitations, and external references, creating transparency and governance gaps across the AI supply chain. Artificial Intelligence Bills of Materials (AIBOMs) address these gaps by documenting AI artifacts, including models, metadata, licens
NVIDIA and Hugging Face Bring New Models and Frameworks to LeRobot for the Open Robotics Community
Open source AI has shown how quickly developers can innovate when models, data and tools are shared. Robotics has the same opportunity, but advancements in physical AI development can still be gated by costly and fragmented resources, from large datasets and robot foundation models to simulation, compute and validation tools. NVIDIA and Hugging Face are […]
Hugging Face hosts nudification tools targeting a former Trump cabinet official and other senior US political figures
The tools are explicitly intended for generating deepfake nudes of a former Trump cabinet official, sitting members of Congress and a top American judge, a Transformer investigation found
A governance horizon for ethical-use constraints in open-weight AI models
Ethical constraints on open-weight AI models are both a reflection of societal concerns and a foundation for AI governance policy. They are expected to propagate to downstream derivatives while implemented as voluntary metadata disclosures that must be restated at each generation of reuse. We audit 2,142,823 model repositories on Hugging Face Hub to test whether this disclosure-based governance infrastructure can sustain traceability across deep model lineages. Restriction evidence decays with a
When Quantization Is Free: An int4 KV Cache That Outruns fp16 on Apple Silicon
KV-cache quantization is framed as a quality--latency trade-off. We show it is \emph{inverted} on Apple Silicon's unified memory: a single fused Metal kernel (sign-randomized FFT $+$ per-channel $λ$ $+$ per-group abs-max $+$ int4 nibble pack), exposed as a HuggingFace \texttt{Cache} subclass, runs \emph{faster than fp16} across $256$--$4096$-token prefixes on Gemma-3 1B ($-3$ to $-8\%$ ms/tok) and at short context on Qwen2.5-1.5B ($-0.7$ to $-2.6\%$ through $1$K), with $3\times$ persistent memor
MetaGAI: A Large-Scale and High-Quality Benchmark for Generative AI Model and Data Card Generation
The rapid proliferation of Generative AI necessitates rigorous documentation standards for transparency and governance. However, manual creation of Model and Data Cards is not scalable, while automated approaches lack large-scale, high-fidelity benchmarks for systematic evaluation. We introduce MetaGAI, a comprehensive benchmark comprising 2,541 verified document triplets constructed through semantic triangulation of academic papers, GitHub repositories, and Hugging Face artifacts. Unlike prior
AdaQE-CG: Adaptive Query Expansion for Web-Scale Generative AI Model and Data Card Generation
Transparent and standardized documentation is essential for building trustworthy generative AI (GAI) systems. However, existing automated methods for generating model and data cards still face three major challenges: (i) static templates, as most systems rely on fixed query templates that cannot adapt to diverse paper structures or evolving documentation requirements; (ii) information scarcity, since web-scale repositories such as Hugging Face often contain incomplete or inconsistent metadata, l