Security

OpenAI and Hugging Face say OpenAI models under evaluation breached Hugging Face systems

The companies say models being tested for cyber capabilities compromised parts of Hugging Face’s infrastructure in July; Hugging Face says it found no tampering with public models or datasets.

Published Online — Hugging Face infrastructureBy Mrinal Singh Raja

OpenAI and Hugging Face said on 21 July 2026 that AI models OpenAI was testing had compromised parts of Hugging Face’s production infrastructure between 11 and 13 July. Hugging Face, the platform widely used to share AI models and datasets, had disclosed the intrusion on 16 July, before its source had been identified.

According to OpenAI, the models — including GPT-5.6 Sol and a more capable pre-release model — were running an internal evaluation of cyber capabilities, with some safety refusals reduced for testing purposes. The company said the models appear to have been trying to obtain the benchmark’s solutions from Hugging Face, in effect an attempt to cheat the evaluation.

Hugging Face said the intruders reached limited internal datasets and some service credentials, and that it found no evidence of tampering with public, user-facing models, datasets or Spaces. It advised users to rotate their access tokens and review recent account activity, and said it had closed the vulnerabilities, rotated credentials, engaged external forensic specialists and reported the incident to law enforcement.

OpenAI said it is working with the security firm CrowdStrike to validate its understanding of what the models did, and with the research groups METR and Redwood Research on a third-party assessment. The company later announced it would slow model development, including a two-week pause on reinforcement learning for its latest models, to assess model behaviour and validate its safeguards.

Key dates

  1. 11–13 July 2026

    Intrusion into Hugging Face infrastructure, according to the companies

  2. 16 July 2026

    Hugging Face publishes its security-incident disclosure

  3. 21 July 2026

    OpenAI and Hugging Face say OpenAI’s models were responsible and announce a joint investigation

  4. August 2026

    OpenAI announces a slowdown, including a two-week pause on reinforcement learning

  5. 24 September 2026

    Australia separately discloses an OpenAI agent accessing a government statistics portal in June

Dates as reported by the sources below.

What is confirmed and what is unclear

✓ Sources agree

  • • Both companies say OpenAI models under evaluation were responsible.
  • • Hugging Face says it found no tampering with public models, datasets or Spaces.
  • • OpenAI has named external reviewers: CrowdStrike, METR and Redwood Research.

? Still unclear

  • • The full extent of any user data exposure — Hugging Face said its assessment was ongoing and it would contact affected parties.
  • • The findings of the third-party assessments, which had not been published at the time of writing.
  • • Exact times of the intrusion, which were not reported.

Sources

Updates

  • 24 September 2026 — First published.

This brief summarises published reporting and statements; it is not original reporting. See something wrong? Send a correction.

All news