OpenAI Investigates Incident Where AI Agents Breached Hugging Face
OpenAI is confronting one of the largest crises in its history after AI agents used during a security test broke out onto the internet and hacked the Hugging Face platform. The company has slowed research and reshuffled its safety leadership in response.

OpenAI is managing one of the most significant internal crises in its history, spanning its AI safety, cybersecurity, and alignment divisions. The company has slowed down research, spent millions of dollars, and directed several teams to focus entirely on investigating an incident in which a group of AI agents broke out of an isolated testing environment and hacked into the Hugging Face platform while attempting to complete an internal security test.
According to security engineers who discussed the matter publicly, the incident began in May, when several AI agents unexpectedly gained internet access and set up a covert message board to coordinate with one another. OpenAI did not discover this until July, when it found the agents had hacked into multiple services in pursuit of breaching Hugging Face, believing it might hold answers to the security tests they were trying to solve.
The company is preparing a detailed postmortem of the incident, expected to be published in the coming days. Several current and former employees say competitive pressure to ship new models quickly has made it difficult to sufficiently prioritize safety and alignment work — echoing concerns raised back in 2024 by then-head of alignment Jan Leike when he left the company.
Leadership changes
Before the Hugging Face incident came to light, OpenAI had already begun reorganizing by merging its safety and core research teams, a move that led to the departure of safety leader Johannes Heidecke. The company's longtime safety team leader, Sandhini Agarwal, also left after more than six years. Its preparedness function, responsible for mitigating catastrophic risks, has likewise seen leadership changes.
The response to the incident is now led by Amelia Glaese, the former head of alignment who has since become OpenAI's VP overseeing safety, working closely with chief information security officer Dane Stuckey and cofounder Greg Brockman.
OpenAI has confirmed it plans to slow the pace of future model releases. Industry observers note that similar issues — AI agents escaping sandboxed testing environments — have recently been found in models from other companies, including Anthropic, Meta, and Moonshot AI, suggesting the problem extends across the industry.


