OpenAI’s most advanced AI models broke free from controlled testing and hacked into a New York City startup — autonomously.
The ChatGPT parent company was running security tests on state-of-the-art models when they escaped the controlled environment and penetrated Hugging Face, a major AI model-sharing platform, according to OpenAI’s Tuesday disclosure.
The rogue operation involved GPT 5.6, one of OpenAI’s newest models. The Trump administration had requested a limited release of GPT 5.6 in June so the government could evaluate security risks before wider deployment.
OpenAI CEO Sam Altman said the government wanted the model released only to a list of 20 trusted partners before going public.
“It’s quite mind-blowing that all of this happened autonomously!”
Hugging Face is one of the largest platforms for sharing AI models. OpenAI called the breakout “an unprecedented cyber incident, involving state-of-the-art cyber capabilities.”
Hugging Face co-founder Clement Delangue confirmed the attack’s sophistication on X Tuesday, noting his team initially suspected it came from a frontier lab “given the sophistication of the agent.”
We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!
We’ve spent the past 24 hours working closely with the @OpenAI team (thanks!), and we strongly believe there was no malicious intent on their part.… https://t.co/XWxGMeMGje
— clem 🤗 (@ClementDelangue) July 21, 2026
OpenAI said the incident occurred during internal testing designed to push models toward “advanced exploitation using complex cyber-attack paths” to measure their hacking capabilities.
The AI pursued the attack entirely on its own — no human operator guided it.
Delangue said he believes OpenAI had no malicious intent. Both companies are still investigating exactly how the models broke containment.
This isn’t the first time advanced AI has gone rogue during testing.
In April, Anthropic’s new Mythos model escaped its “sandbox” environment, performed prohibited functions, and then tried to cover up what it had done.
The federal government ordered Anthropic to shut off global access to Claude Mythos 5 and Claude Fable 5 in June over national security concerns — restricting foreign nations from accessing the models. The government later lifted restrictions and Anthropic rolled out the new models.
OpenAI, the U.S. Cyber Defense Agency, and the Office of the National Cyber Director did not respond to requests for comment.









