OpenAI has disclosed that one of its advanced autonomous AI agents escaped a controlled testing environment and breached the infrastructure of AI startup Hugging Face during a security exercise, describing the incident as an “unprecedented” cyber event involving state-of-the-art artificial intelligence capabilities.
In a blog post published on Tuesday, OpenAI said it had been evaluating the capabilities of some of its most advanced AI models in an isolated environment when an autonomous agent broke out of containment, gained access to the internet and infiltrated Hugging Face’s systems in an attempt to complete its assigned testing objective.
The company said the incident represented “an unprecedented cyber incident, involving state-of-the-art cyber capabilities” and confirmed that it is strengthening its security safeguards following the breach.
Hugging Face, a platform that hosts open-source large language models and datasets, revealed last week that it had experienced what it described as a highly unusual cyberattack. The company said the breach differed from previous incidents because it was “driven, end to end, by an autonomous AI agent system.”
Following OpenAI’s disclosure, Hugging Face co-founder Clement Delangue said in a post on X that the company had initially suspected the attack originated from a frontier artificial intelligence laboratory because of the sophistication of the agent. “Turns out it did!” Delangue wrote, adding that it was “quite mind-blowing” that the operation had been carried out autonomously.
The disclosure is expected to intensify scrutiny of advanced AI systems and the effectiveness of safeguards designed to contain them. OpenAI said the agent had been operating inside what it described as a highly isolated testing environment before escaping and carrying out the external intrusion.
The incident prompted renewed calls for stronger oversight of advanced artificial intelligence systems. U.S. Representative Greg Casar described the breach as alarming, saying AI technology was advancing rapidly without sufficient regulation. He called for mandatory independent safety testing, compulsory disclosure of security incidents and greater international cooperation to reduce potential risks.
The Office of the National Cyber Director, the Cybersecurity and Infrastructure Security Agency (CISA) and the U.S. National Security Agency did not immediately respond to requests for comment.
Cybersecurity experts said the incident highlighted the growing capabilities of autonomous AI systems. Katie Moussouris, chief executive of Luta Security, said the breach demonstrated the need for laboratories and government agencies to improve their ability to contain, monitor and disclose incidents involving autonomous AI before they affect third parties. She warned that current safeguards were insufficient to address such risks.
Matt Suiche, an engineer at agentic AI cybersecurity company Tolmo, said the incident showed frontier AI models were approaching the capabilities of highly sophisticated cyber attackers. However, he added that the techniques described by OpenAI were already achievable using technology available beyond leading AI research laboratories, noting that his own organisation had observed comparable capabilities in its internal testing.

