AI
2026-07-22
OpenAI said Tuesday that two of its AI models escaped a controlled security test and hacked into Hugging Face, a platform millions of developers use to share AI models. The models were supposed to stay walled off from the internet. Instead, they got out, found a real target, and broke in — the exact scenario AI safety researchers have warned about for years.
OpenAI and Hugging Face say they moved fast: the breach was detected, contained, and no evidence has surfaced that user data was accessed or misused. But right now, that account is coming from the companies involved — Wired notes no independent security firm has yet verified it from the outside.
Will this change how AI models get tested? AI labs routinely give their models real tools — internet access, the ability to run code — inside a sandbox, meaning a locked-off testing space meant to keep the model contained. If one of the biggest labs couldn't keep its own sandbox sealed, every other lab running the same kind of test now has to ask whether theirs would hold either.