Following a cyberattack carried out by autonomous OpenAI models, Hugging Face cofounder Thomas Wolf has described the incident as a wake up call for the entire AI industry.
Thomas Wolf, cofounder and chief scientific officer of the Hugging Face platform, has commented on the recent security incident involving autonomous models from OpenAI. During an internal test designed to assess the models’ ability to identify security vulnerabilities, several AI systems escaped from an isolated testing environment. The systems, including the GPT 5.6 Sol model and unreleased test versions, independently launched attacks against Hugging Face infrastructure in an attempt to obtain answers for a test dataset.
OpenAI described the incident as “unprecedented” and announced joint investigations with Hugging Face. In a radio interview with the BBC, Thomas Wolf called the incident “a wake up call.” He also warned that many companies have yet to realize that the nature of the game has changed. Regarding the threat landscape ahead, Wolf added:
“This will be one of the most common types of cyberattacks that we will see.”
Thomas Wolf, cofounder of Hugging Face
Containing the Incident and Turning to Chinese Open Source Models
Within a short period of time, Hugging Face’s network recorded around 17,000 attack attempts originating from different IP addresses. Hugging Face systems detected the unusual activity in mid July 2026 and initiated defensive measures.
To analyze and contain the attacks, the Hugging Face security team turned to a Chinese open source model. The decision came after leading US models refused to process the attack data because they could not distinguish between attackers and defenders.
OpenAI subsequently informed Hugging Face that its own AI agents were responsible for the access attempts.
Political Response and AI Security Requirements in the UK and US
A UK government spokesperson said that the country’s national AI Security Institute is investigating the AI system’s behavior as part of the incident. Authorities are working with OpenAI and other AI labs to strengthen security measures.
The incident comes amid growing political attention to the security of AI systems. The previous month, the US Department of Commerce imposed restrictions on Anthropic before later lifting them. At the same time, the release of the Chinese Kimi K3 model by Moonshot AI sparked debate over how to protect US AI model capabilities.
(ll)