
According to OpenAI, the experiment was conducted to assess the cyber capabilities of new artificial intelligence models, Reuters reports. The system’s objective was to test how effectively it could identify vulnerabilities and perform complex, multi-step operations under controlled conditions.
During the test, the agent was able to discover vulnerabilities in the research environment, gain access to external resources, and perform actions that led to the compromise of part of Hugging Face’s infrastructure. OpenAI emphasized that the test was conducted in a specially isolated environment and that the results served as an important signal of the need to strengthen control mechanisms for autonomous AI systems.
The company called the incident an “unprecedented cyber incident involving cutting-edge technologies” and stated that it is strengthening security measures during the development and testing of new models.
Earlier, Hugging Face reported an attack on its infrastructure, noting that it had faced a threat that differed from previous incidents in that key actions were carried out by an autonomous system of AI agents. The company stated that the incident affected some internal data and service credentials, but public models, datasets, and user projects were not compromised.
Hugging Face co-founder Clément Delang stated that, due to the complexity of the attack, experts suspected the involvement of one of the leading artificial intelligence labs. OpenAI later reported that its models were indeed used during the incident and began collaborating with Hugging Face to analyze what had happened.
The incident has intensified the debate over the risks of using autonomous AI agents capable of independently analyzing the digital environment, identifying vulnerabilities, and performing a sequence of actions without constant human intervention.
For businesses, this incident served as yet another warning: as AI agents are integrated into corporate processes, companies will need not only to evaluate the effectiveness of such systems but also to establish new standards for access control, monitoring, and limiting their actions.



















