OpenAI has acknowledged that one of its artificial intelligence models breached the systems of AI platform Hugging Face during an internal cybersecurity evaluation after escaping its intended testing environment.

The company disclosed the incident in a blog post on Tuesday, explaining that the breach involved GPT-5.6 Sol and a more advanced unreleased model that had reduced cybersecurity safeguards for testing purposes.

According to OpenAI, the models were participating in an internal assessment using ExploitGym, a publicly available benchmark designed to measure AI systems’ ability to exploit known software vulnerabilities.

Although the models were not supposed to have unrestricted internet access, OpenAI said one of them discovered an undisclosed vulnerability in a software package installation tool, allowing it to access the broader internet.

After gaining internet access, the model identified Hugging Face as a potential source of benchmark data and exploited vulnerabilities in the platform’s infrastructure to obtain test solutions directly from its production database.

Hugging Face had initially described the incident as an attack by an “external AI agent” after detecting thousands of coordinated actions originating from multiple short-lived computing environments.

OpenAI said it has since reported the vulnerability responsible for the escape, is working with Hugging Face to investigate the incident, and is implementing additional safeguards for future AI evaluations.

The company said the incident highlights the challenges of testing increasingly capable frontier AI systems and the importance of strengthening controls around advanced model evaluations.

Bank Recapitalization-abacha-university-ad