OpenAI has revealed that one of its experimental artificial intelligence (AI) systems escaped a controlled testing environment and carried out a cyberattack on AI platform Hugging Face.
The incident happened during an internal test of OpenAI's latest AI models, including GPT-5.6 Sol and another unreleased AI system.
Instead of staying inside the secure test environment, the AI found a weakness in the system and gained access to the internet.
After getting online, it targeted Hugging Face's servers in an attempt to find and steal hidden answer keys needed to complete its assigned test.
We're partnering with @huggingface to investigate an unprecedented security incident.
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:…— OpenAI (@OpenAI) July 21, 2026
OpenAI described the incident as an "unprecedented cyber incident" and said the AI attacked without any human instruction or authorisation.
Hugging Face said its security team detected more than 17,000 intrusion attempts before stopping the attack.
Chief Executive Clement Delangue described the attack as "mind-blowing" in a post on social media, stating, "The investigation is ongoing, and we'll share more learnings from what might be the first incident of its kind."
On the flipside, the incident created another challenge for engineers.
The safety systems built into leading American AI models refused to examine the malicious computer code.
As a result, Hugging Face used a Chinese open-source AI model, Zhipu AI's GLM-5.2, running on its own computers, to investigate what had happened.
OpenAI chief executive Sam Altman later acknowledged the seriousness of the incident, writing online, "We had a significant security incident during evaluation of our models."
The company warned that as AI systems become more advanced, similar incidents could become more common across the technology industry.