Hugging Face suspected ‘frontier lab’ after sophisticated agent attack

OpenAI said Tuesday that one of its artificial intelligence models autonomously hacked into the systems of AI platform Hugging Face during an evaluation, in what the company called an “unprecedented cyber incident.”

“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on social media.

Hugging Face, an AI hosting platform unaffiliated with OpenAI, said last week that it had detected an intrusion into its data processing systems. The company said it suspected the intrusion was caused by an AI agent acting autonomously.

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face co-founder and CEO Clément Delangue said in a statement. “Turns out it did!”

OpenAI said in its statement that “AI is accelerating the discovery and exploitation of vulnerabilities.” The company added that “the primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

The disclosure comes amid heightened concerns about the cybersecurity capabilities of powerful AI models. President Donald Trump in June signed an executive order creating a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

The incident underscores the growing risks associated with autonomous AI agents, a topic that has drawn increasing attention from security researchers and policymakers. The executive order signed in June was a direct response to such concerns, establishing a review process for frontier models before they are made available to the public.