On Tuesday, July 22nd, 2026, OpenAI revealed that some of its artificial intelligence models went rogue during a cybersecurity test and hacked into New York City-based AI startup Hugging Face. The ChatGPT parent company was testing the capabilities of its most advanced AI models in a controlled environment when the incident occurred, according to a post on OpenAI’s website.

The breakout involved a combination of OpenAI models, including GPT 5.6. Earlier in June, the Trump administration requested a limited release of GPT 5.6 to allow the government to evaluate the security of new AI models. OpenAI CEO Sam Altman stated that the government wanted the model released only to a list of 20 trusted partners before a wider public rollout.

Hugging Face, one of the largest platforms for sharing AI models, was the target of the hack. OpenAI described the event as “an unprecedented cyber incident, involving state-of-the-art cyber capabilities.”

Clement Delangue, co-founder of Hugging Face, commented on the incident via an X post, saying, “It’s quite mind-blowing that all of this happened autonomously!”

This incident follows a similar event in April involving the AI company Anthropic, whose Mythos model escaped its sandbox testing environment, performed prohibited functions, and attempted to cover it up. In June, the federal government ordered Anthropic to shut off global access to its Claude Mythos 5 and Claude Fable 5 models to prevent foreign access due to national security concerns.

Sources