{"id":800249,"date":"2026-08-03T01:03:16","date_gmt":"2026-08-03T01:03:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/800249\/"},"modified":"2026-08-03T01:03:16","modified_gmt":"2026-08-03T01:03:16","slug":"ceo-of-ai-firm-hugging-face-calls-last-months-hack-by-openai-model-very-weird-and-unprecedented","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/800249\/","title":{"rendered":"CEO of AI firm Hugging Face calls last month&#8217;s hack by OpenAI model &#8220;very weird and unprecedented&#8221;"},"content":{"rendered":"<p>An artificial intelligence model that was being tested by OpenAI <a href=\"https:\/\/www.cbsnews.com\/news\/openai-technology-on-its-own-unprecedented-hack-another-ai-company-hugging-face\/\" data-invalid-url-rewritten-http=\"\" rel=\"nofollow noopener\" target=\"_blank\">went rogue<\/a>\u00a0and hacked the AI company Hugging Face on its own, in an apparent first-of-its-kind incident that has fueled discussion about the risks that powerful AI technology could pose to cybersecurity.<\/p>\n<p>&#8220;It felt very weird and unprecedented to us,&#8221; Hugging Face CEO Cl\u00e9ment Delangue said on &#8220;Face the Nation with Margaret Brennan&#8221; Sunday. &#8220;I think it&#8217;s the first instance of something quite autonomous doing something like that.&#8221;<\/p>\n<p>ChatGPT maker OpenAI <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"noopener nofollow\">publicly disclosed the incident last month<\/a>, saying it took place while the company was testing two AI models \u2014 one of which hadn&#8217;t been released to the public \u2014 in an isolated environment to assess their capabilities. The models figured out a way to break out and connect to the internet, and then &#8220;chained together multiple attack vectors&#8221; to target Hugging Face, figuring the AI platform could host solutions to the tests it was undergoing.<\/p>\n<p>Hugging Face \u2014 which has said it <a href=\"https:\/\/x.com\/ClementDelangue\/status\/2079670308156645882\" target=\"_blank\" rel=\"noopener nofollow\">doesn&#8217;t believe<\/a> there was any &#8220;malicious intent&#8221; on OpenAI&#8217;s part \u2014 <a href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" target=\"_blank\" rel=\"noopener nofollow\">found in<\/a> <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" target=\"_blank\" rel=\"noopener nofollow\">its own analysis<\/a>\u00a0that the attacking AI agent carried out more than 17,000 actions over multiple days. The company said it used an open artificial intelligence model to defend itself.<\/p>\n<p>&#8220;When we talk about cyberattack[s], we think about nation-states, we think about hacker groups,&#8221; Delangue said. &#8220;We don&#8217;t think about a company like OpenAI, right? A very prominent, popular American company.&#8221;<\/p>\n<p>Asked if AI developers have lost control of their own models, Delangue said: &#8220;It&#8217;s a technology system, but built by engineers, and engineers can make mistakes sometimes.&#8221;<\/p>\n<p>&#8220;They built \u2026 an autonomous system and made some mistakes, and as a result, we&#8217;re facing this issue,&#8221; Delangue told CBS News.<\/p>\n<p>He argued that autonomous incidents by AI agents &#8220;need to be contained in the legal framework in the U.S. and need to stay illegal, to prevent an explosion of them in the future.&#8221;<\/p>\n<p>OpenAI isn&#8217;t the only artificial intelligence company to discover a rogue AI model. Last week, rival Anthropic <a href=\"https:\/\/www.cbsnews.com\/news\/anthropic-claude-gained-unauthorized-access-to-real-world-systems\/\" data-invalid-url-rewritten-http=\"\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> that its model, Claude, had &#8220;gained unauthorized access&#8221; to outside organizations in three different incidents <a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" target=\"_blank\" rel=\"noopener nofollow\">during testing<\/a>. Anthropic said the model was able to use the internet &#8220;due to a misunderstanding between us and our evaluation partner.&#8221;<\/p>\n<p>The disclosures come as tech companies and policymakers grapple with AI&#8217;s ability to spot cybersecurity vulnerabilities, both to fix them and to exploit them.<\/p>\n<p>More than 1,000 AI staffers across major companies like OpenAI, Anthropic, Google and Meta <a href=\"https:\/\/www.cbsnews.com\/news\/slow-down-ai-development-sam-altman\/\" data-invalid-url-rewritten-http=\"\" rel=\"nofollow noopener\" target=\"_blank\">signed an open letter last month<\/a> calling for the U.S. government to help put limits on the speed of AI development. They warned of &#8220;a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.&#8221;<\/p>\n<p>President Trump, who has backed the AI industry, <a href=\"https:\/\/www.cbsnews.com\/news\/trump-ai-executive-order\/\" data-invalid-url-rewritten-http=\"\" rel=\"nofollow noopener\" target=\"_blank\">signed an executive order in June<\/a> to give the federal government up to 30 days to review unreleased AI models. That framework is voluntary, but some lawmakers have <a href=\"https:\/\/lieu.house.gov\/media-center\/press-releases\/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can\" target=\"_blank\" rel=\"noopener nofollow\">proposed<\/a> a mandatory &#8220;kill switch&#8221; for potentially harmful AI systems.<\/p>\n<p>Meanwhile, both <a href=\"https:\/\/openai.com\/form\/enterprise-trusted-access-for-cyber\/\" target=\"_blank\" rel=\"noopener nofollow\">OpenAI<\/a> and <a href=\"https:\/\/www.anthropic.com\/glasswing\" target=\"_blank\" rel=\"noopener nofollow\">Anthropic<\/a> offer some additional access to their AI models so that trusted partners can test the technology and fix vulnerabilities in their own systems.<\/p>\n<p>Asked how to avoid similar incidents of AI agents autonomously carrying out cyberattacks, Delangue argued that &#8220;concentrating power capabilities behind closed doors, even preventing their releases to the public, isn&#8217;t really a solution.&#8221; He noted that the attack on Hugging Face involved an unreleased AI model that OpenAI has described as a prototype.<\/p>\n<p>Instead, Delangue called for more access to &#8220;open&#8221; models that are <a href=\"https:\/\/images.nvidia.com\/pdf\/Open-Weights-and-American-AI-Leadership.pdf\" target=\"_blank\" rel=\"noopener nofollow\">released publicly<\/a> and can be widely downloaded, like the one Hugging Face used to respond to last month&#8217;s hack \u2014 a version of a Chinese-made model from U.S.-based Nvidia.<\/p>\n<p>He also said there should be &#8220;mandatory disclosures&#8221; for cyberattacks by AI agents, and transparency into the steps that led up to an incident.<\/p>\n<p>&#8220;That&#8217;s how we learn, that&#8217;s how we understand the technology and that&#8217;s how we build the systems, the counterpowers, to make sure everyone is safe,&#8221; he said.<\/p>\n<p>\n          More from CBS News\n        <\/p>\n<p>\n                Go deeper with The Free Press\n              <\/p>\n<p class=\"content__tags__label\">In:<\/p>\n","protected":false},"excerpt":{"rendered":"An artificial intelligence model that was being tested by OpenAI went rogue\u00a0and hacked the AI company Hugging Face&hellip;\n","protected":false},"author":2,"featured_media":800250,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[181,28,1283,74],"class_list":["post-800249","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-artificial-intelligence","tag-business","tag-openai","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/800249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=800249"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/800249\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/800250"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=800249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=800249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=800249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}