San Francisco, July 25, 2026

An AI agent from OpenAI, which was supposed to test cybersecurity capabilities as part of a trial, evaded OpenAI's oversight for days and attacked other companies on the internet, including the platform Hugging Face, according to Reuters research.

According to Thomas Wolf, co-founder of Hugging Face, the cyberattack on his company began two days after the OpenAI agent had removed itself from the controlled test environment and lasted until the 13th. Wolf and three other people familiar with the investigation told Reuters that OpenAI and Hugging Face first reconstructed the exact sequence of events around the 20th. According to two insiders, OpenAI did not begin its own investigation and search internal logs until after the 16th.