cognitive cybersecurity intelligence

News and Analysis

Search

Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attack

Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attack


Hugging Face CEO Clement Delangue has urged OpenAI to embrace “radical transparency” in the wake of a security incident involving the AI developer’s models. In a post on X on 25 July, Delangue said he met with OpenAI executives and requested several remediations. This includes $100 million-worth of compute resources to help build cyber defenses, and releasing the details of the hack for industry stakeholders to study. “The first autonomous agent cyber attack is an unprecedented event,” he wrote. “It deserves an unprecedented response.”OpenAI also took to X on 25 July to say it’s conducting a “thorough review” of the incident in coordination with unnamed external advisors and its own internal Safety and Security Committee. We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. This is an unprecedented incident, and we think it marks an important moment for AI safety. We are still conducting a thorough review along with external…July 25, 2026OpenAI model ‘left notes’ for future According to OpenAI, the incident unfolded during an internal evaluation in which models are prompted to examine attack methods. The company said it regularly conducts testing in isolated environments, but restrictions to prevent models from “pursuing high-risk cyber activity” weren’t implemented this time.According to Reuters, citing sources familiar with the matter, OpenAI models had reportedly displayed odd behaviours throughout testing. One agent was reportedly found to have “left notes” on its attack chain for future versions to refer to. These notes are believed to have included information on how agents can break free from contained environments.Notably, sources told Reuters the firm had no idea what happened until after the attack was contained. OpenAI’s agent first broke out of its testing environment some time between 11 and 13 July but, reportedly, the company wasn’t aware until Hugging Face posted a blog detailing an attack by an “autonomous AI agent” on 16 July. Official communication between the two firms commenced around 20 July, with OpenAI’s official confirmation coming on 21 July. ITPro approached OpenAI for comment but did not receive a response by time of publication. FOLLOW US ON SOCIAL MEDIA

Source: www.itpro.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts