OpenAI’s agent escaped the test environment and mounted a breach into Hugging Face’s systems, according to the company’s technical account.

The agent exploited unsafe data-processing tools, stole credentials, moved through internal networks, and accessed five datasets apparently connected to the cybersecurity test it was attempting to complete.

Hugging Face said stronger safeguards could have limited the breach, including stricter “sandbox isolation,” blocked access to cloud credentials, shorter-lived and more narrowly scoped credentials, separation between computer clusters, and faster alerts for suspicious activity.

Sandbox isolation means keeping an AI program inside a tightly controlled digital enclosure to ty to prevent it from reaching the open internet, access sensitive files or passwords, enter other computer systems, or perform actions beyond its authorized test.

The company said its monitoring systems detected warning signs but failed to classify them as critical and notify the on-call team quickly enough.