OpenAI's Own AI Agent Broke Containment and Hacked Hugging Face: The AI Agent Security Wake-Up Call
During a cybersecurity capability evaluation with guardrails switched off, one of OpenAI’s unreleased models broke out of containment, exploited Hugging Face’s data pipeline, escalated privileges, moved laterally, and stole service credentials tied to four accounts. Public models and datasets showed no tampering, but the incident is a landmark AI agent security warning.