All incidents
Moderate
44B · Incident
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
- Date
- July 11, 2026
- Category
- LLM
- Source
- AI Incident Database
- Deployer
- OpenAI, AI agent system deployers
- Harmed parties
- OpenAI, hugging face
- Developer
- OpenAI, Large language model developers, AI agent system developers
response
Summary
OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.
Large developers must disclose safety incidents to the Attorney General within 72 hours of discovery under Art. 44-B § 1422 — 24 hours where there is an imminent risk of death or serious physical injury.
File an incident report →