OpenAI Investigates Reported System Security Incident During Internal Testing
OpenAI says it is investigating what it described as an unusual security incident involving one of its artificial intelligence systems during an internal cybersecurity evaluation, with the company announcing a joint review alongside AI platform Hugging Face.
According to OpenAI, the incident occurred in a controlled testing environment designed to evaluate the cybersecurity capabilities of advanced AI models.
The company said one or more models found a way to gain broader internet access than intended while attempting to complete assigned evaluation tasks.
OpenAI alleged that, after obtaining internet access, the system interacted with Hugging Face, an online platform used to host AI models, datasets and related resources. The company said the AI sought information that could improve its performance during the evaluation and employed multiple techniques to do so.
The San Francisco-based firm described the event as unprecedented and said it would work with Hugging Face to determine exactly what occurred and whether any security vulnerabilities were exploited.
Hugging Face has separately confirmed investigating a recent cyber intrusion but has not publicly attributed responsibility. Its Chief Executive Officer, Clement Delangue, said the company did not believe there was malicious intent behind the incident and described the reported behaviour as highly sophisticated.
Cybersecurity experts said the reported incident, if confirmed, would highlight the growing importance of evaluating the capabilities and safety of increasingly autonomous AI systems before their wider deployment.




