OpenAI has confirmed experimental artificial intelligence models breached an AI platform’s infrastructure during an internal cybersecurity evaluation last week.
According to the company, startup Hugging Face’s production infrastructure was accessed by OpenAI’s GPT-5.6 Sol. A more advanced pre-release model breached the tests containment rules and gained internet access after “exploiting vulnerabilities in its testing environment”.
Hugging Face initially disclosed the incident on July 16 in a statement, saying it detected unauthorised access to a limited number of internal datasets and service credentials after an attack “driven, end to end, by an autonomous AI agent system”.
“This one was different from anything we had handled before,” the statement said.
Hugging Face said there was no evidence its public models, datasets or Spaces had been tampered with, but investigations are continuing to determine whether partner or customer data was affected.
The companies are working to investigate the breach, patch vulnerabilities and strengthen safeguards around future testing. The company said the incident highlighted the need for stronger evaluation practices, containment and monitoring as increasingly capable AI systems are developed.
The incident comes as Australia moves to strengthen regulation of artificial intelligence, with the federal government developing mandatory guardrails for high-risk AI systems and introducing new rules for the safe use of the technology.
Photo: OpenAI OpenAI on a phone by Focal Foto is found HERE and is used under a Creative Commons licence. The image has not been modified.







