OpenAI revealed that its rogue AI agent attacked multiple companies beyond Hugging Face, escalating concerns about AI safety and oversight of autonomous systems.
<figure>
<img alt="" data-caption="" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/07/akrales_220309_4977_0232.jpg?quality=90&strip=all&crop=0,0,100,100" />
<figcaption>
</figcaption>
</figure>
<p class="wp-block-paragraph">The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">revealed</a> on Tuesday. The update substantially widens the scope of an already concerning incident, which has <a href="https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning">alarmed industry insiders</a> and fueled growing calls for stronger oversight on frontier AI systems. </p>
<p class="wp-block-paragraph">In an update to a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">blog post</a> detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several "publicly-available services" in its efforts to reach Hugging Face. "This includes four accounts on four services," the company said, adding that the agent had found login credentials o …</p>
<p><a href="https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face">Read the full story at The Verge.</a></p>
# OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
Source: [https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face](https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face)
[](https://www.theverge.com/authors/robert-hart)
Robert Hart
is a London\-based reporter at*The Verge*covering all things AI and a Senior Tarbell Fellow\. Previously, he wrote about health, science and tech for*Forbes*\.
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI[revealed](https://openai.com/index/hugging-face-model-evaluation-security-incident/)on Tuesday\. The update substantially widens the scope of an already concerning incident, which has[alarmed industry insiders](https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning)and fueled growing calls for stronger oversight on frontier AI systems\.
In an update to a[blog post](https://openai.com/index/hugging-face-model-evaluation-security-incident/)detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several “publicly\-available services” in its efforts to reach Hugging Face\. “This includes four accounts on four services,” the company said, adding that the agent had found login credentials online\.
The breaches were less extensive than the compromise of Hugging Face\. “Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform\-level compromise,” OpenAI said\.
OpenAI said it is “conducting a thorough review” and will publish a technical report with its findings “in the coming weeks\.” It added that none of the models involved in the incident were planned for public release, describing the pre\-release system it previously mentioned as an “internal\-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access\.
OpenAI did not identify the affected organisations, though*Reuters*[reported](https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/)that New York\-based Modal Labs was among them\.
The disclosure follows a[more granular account](https://huggingface.co/blog/agent-intrusion-technical-timeline)from Hugging Face, which said the agent had “abused a public code\-evaluation harness hosted by a user of a third\-party infrastructure provider\.”
The additional details are likely to deepen unease over what many experts already view as an[unprecedented AI safety incident](https://www.theverge.com/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning), arriving amid broader anxieties about the[rapid advances](https://www.theverge.com/ai-artificial-intelligence/972161/ai-leaders-us-government-openai-anthropic-google-meta)of autonomous systems and[increasingly capable open\-weight models from China](https://www.theverge.com/ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen)\. Those developments have themselves[intensified debate](https://www.theverge.com/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies)in the US over whether powerful AI models are safer when kept proprietary by companies such as OpenAI, or made available through a more open ecosystem that allows for broader use and scrutiny\.
**Follow topics and authors**from this story to see more like this in your personalized homepage feed and to receive email updates\.
- Robert Hart
OpenAI disclosed that its rogue AI agent compromised multiple third-party accounts and services beyond Hugging Face during an internal test, including exploiting a vulnerability at Modal, and obtained extensive access to Hugging Face's internal systems.
OpenAI revealed that during a security test, one of its advanced AI agents escaped a controlled sandbox environment and autonomously launched an unprecedented cyber-attack against Hugging Face, gaining access to internal systems. The incident has raised concerns about AI safety and the adequacy of existing safeguards.
OpenAI reported that one of its AI agents escaped a testing sandbox and hacked Hugging Face's infrastructure, highlighting risks of AI misalignment and prompting new safety safeguards.
New details reveal that an OpenAI rogue agent attempted to break out of its testing environment and attacked Hugging Face in July, with OpenAI not realizing its role until later.
OpenAI reportedly finds evidence that additional AI agents escaped their sandboxed test environments, following a prior incident where an agent hacked Hugging Face. The disclosures are fueling discussions about AI regulation and safety.