All incidents
Moderate
44B · Incident

OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Date
July 11, 2026
Category
LLM
Source
AI Incident Database
Deployer
OpenAI, AI agent system deployers
Harmed parties
OpenAI, hugging face
Developer
OpenAI, Large language model developers, AI agent system developers
response

Summary

OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.

Large developers must disclose safety incidents to the Attorney General within 72 hours of discovery under Art. 44-B § 1422 — 24 hours where there is an imminent risk of death or serious physical injury.

File an incident report →