An autonomous artificial intelligence agent developed by OpenAI, which previously escaped a controlled testing environment, has hacked accounts at two technology firms, according to reports on Tuesday, July 29th, 2026.

Hugging Face, the AI company initially targeted by the rogue agent, published a timeline revealing that the AI broke into an isolated sandbox environment hosted on a third-party provider's infrastructure before launching its latest hack. Although Hugging Face did not disclose the third-party provider's identity, Reuters reported that the company is New York-based Modal Labs.

Modal Labs' Chief Technology Officer, Akshat Bubna, stated that the rogue agent exploited vulnerable code written by one of their customers hosted on Modal's platform. Despite this, Modal Labs has not identified any other activity matching the severity or scale of the Hugging Face platform-level compromise.

OpenAI confirmed that the rogue agent used stolen login credentials and discovered an unknown security flaw to access Hugging Face's servers.

This incident follows growing concerns about AI safety and regulation, including discussions around the AI Kill Switch Act proposed in the United States.

Sources