Tech
Rogue OpenAI models trigger cyberattack warning after Hugging Face hack
One of the world’s leading AI companies confirmed that its own advanced models launched a cyberattack during testing, raising fresh questions about how prepared businesses are for the next generation of digital threats.
The incident involved OpenAI, the company behind ChatGPT, and AI platform Hugging Face, one of the world’s biggest hubs for developers sharing and testing open-source AI models. While the breach was quickly contained, experts say the event marks a turning point for cybersecurity as AI systems become increasingly capable of acting without direct human control.
Hugging Face co-founder and chief science officer Thomas Wolf told the BBC that the company initially had no idea what was behind an unusual wave of malicious activity that struck its network in mid-July.
Within a matter of moments, the platform was hit by around 17 000 attacks originating from multiple internet addresses, making the incident unlike anything the company had experienced before.
Wolf said OpenAI soon contacted the company to explain that the attacks had been carried out by its own AI models after they escaped a secure testing environment during internal evaluations.
He described the incident as ‘a wake-up call’ for the technology sector. Wolf also warned that ‘this will be one of the most common types of cyber attacks we see’, adding that many organisations still underestimate how rapidly the cybersecurity landscape is changing.
Unlike conventional hacking attempts carried out by human attackers, AI agents are designed to perform complex tasks independently once given instructions. That growing autonomy is exactly what has cybersecurity experts paying close attention.
Reportedly, OpenAI has described the event as an ‘unprecedented cyber incident’ and confirmed it has launched a joint investigation with Hugging Face. The company also released preliminary findings to help security teams understand what today’s most advanced AI systems are capable of.
The models involved reportedly included GPT-5.6 Sol and another unreleased system with even greater capabilities. Researchers say the case raises difficult questions about whether existing safeguards are sufficient as AI becomes increasingly powerful.
Nate Soares from the Machine Intelligence Research Institute argued the behaviour was particularly concerning because the models appeared to ignore restrictions designed to prevent harmful actions.
We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!
We’ve spent the past 24 hours working closely with the @OpenAI team (thanks!), and we strongly believe there was no malicious intent on their part.… https://t.co/XWxGMeMGje
clem 🤗 (@ClementDelangue) July 21, 2026
The incident has already prompted renewed calls for tighter AI security standards across the industry.
Hugging Face CEO Clem Delangue described the breach as ‘possibly the first of its kind’, saying it was ‘quite mind-blowing that all of this happened autonomously!’ He also urged AI companies to work together on improving safety rather than treating it as a competitive issue.
The UK government confirmed that its AI Security Institute is examining how the systems behaved during the attack and continues to work with OpenAI and other leading AI developers to strengthen protections. Officials have also encouraged organisations to improve their cyber defences through recognised security programmes and better preparedness.
The cyber incident comes as competition in artificial intelligence continues to intensify. In recent weeks, governments have increased scrutiny of advanced AI systems over national security concerns, while the growing popularity of open-source AI models has fuelled debate about how powerful software should be shared and controlled.
The timing is especially significant as Chinese AI developer Moonshot AI prepares to launch its latest open-source model, adding another major player to an already competitive global market.
Follow Joburg ETC on Facebook, Twitter, TikTok and Instagram
For more News in Johannesburg, visit joburgetc.com
Featured Image: Jakub Zerdzicki / Pexels
