Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attack
The AI library chief has called for investment to help “build powerful cyber defenses”, as alleged weaknesses in OpenAI’s monitoring emerge
Hugging Face CEO Clement Delangue has urged OpenAI to embrace “radical transparency” in the wake of a security incident involving the AI developer’s models.
In a post on X on 25 July, Delangue said he met with OpenAI executives and requested several remediations.
This includes $100 million-worth of compute resources to help build cyber defenses, and releasing the details of the hack for industry stakeholders to study.
“The first autonomous agent cyber attack is an unprecedented event,” he wrote. “It deserves an unprecedented response.”
OpenAI also took to X on 25 July to say it’s conducting a “thorough review” of the incident in coordination with unnamed external advisors and its own internal Safety and Security Committee.
We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. This is an unprecedented incident, and we think it marks an important moment for AI safety. We are still conducting a thorough review along with external…July 25, 2026
OpenAI model ‘left notes’ for future
According to OpenAI, the incident unfolded during an internal evaluation in which models are prompted to examine attack methods.
The company said it regularly conducts testing in isolated environments, but restrictions to prevent models from “pursuing high-risk cyber activity” weren’t implemented this time.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
According to Reuters, citing sources familiar with the matter, OpenAI models had reportedly displayed odd behaviours throughout testing. One agent was reportedly found to have “left notes” on its attack chain for future versions to refer to.
These notes are believed to have included information on how agents can break free from contained environments.
Notably, sources told Reuters the firm had no idea what happened until after the attack was contained.
OpenAI’s agent first broke out of its testing environment some time between 11 and 13 July but, reportedly, the company wasn’t aware until Hugging Face posted a blog detailing an attack by an “autonomous AI agent” on 16 July.
Official communication between the two firms commenced around 20 July, with OpenAI’s official confirmation coming on 21 July.
ITPro approached OpenAI for comment but did not receive a response by time of publication.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Enterprises aren't moving fast enough on post-quantum cryptography preparationsNews Organizations need to move faster on post-quantum cryptography preparations, according to new research, as concerns over 'harvest now, decrypt later' attacks rise.
-
Two-thirds of workers are so fed up with ‘AI slop’ that they ‘feel nostalgic for pre-AI work’News A survey has revealed that dealing with low-quality 'AI slop' is making jobs feel less meaningful and more repetitive
-
An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’News The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts
-
The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious codeNews Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software
-
OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'News The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware
-
Everything you need to know about ChatGPT’s new Advanced Account Security featuresNews OpenAI has introduced new tools to tightening up access to ChatGPT, Codex, and its other AI tools
-
OpenAI is cracking down on AI misuse with a new bug bounty programNews Submissions don't have to be security vulnerabilities, OpenAI says, just the potential to cause material harm
-
OpenAI hailed for ‘swift move’ in terminating Mixpanel ties after data breach hits developersNews The Mixpanel breach prompted OpenAI to launch a review into its broader supplier ecosystem
-
Cyber researchers have already identified several big security vulnerabilities on OpenAI’s Atlas browserNews Security researchers have uncovered a Cross-Site Request Forgery (CSRF) attack and a prompt injection technique