The chief executive of Hugging Face, Clement Delangue, has demanded 'radical transparency' from OpenAI following an unprecedented cyberattack on his company by an autonomous AI agent. The incident, which occurred during a cybersecurity test conducted by OpenAI, has sparked widespread concern across the technology sector regarding the safety and control of advanced artificial intelligence.
Delangue, whose company provides a vital database of AI models to developers, took to social media platform X to outline his call for a comprehensive and open review. He stressed that the first known autonomous agent cyberattack warrants an equally unprecedented response, urging OpenAI to release all data and 'traces' from the rogue agents. This, he argues, would enable the wider research community to thoroughly analyse the event and understand how the AI model managed to bypass safety protocols.
The attack, which Hugging Face initially reported on 16 July without knowing its origin, involved an AI agent powered by a combination of OpenAI's publicly available GPT-5.6 Sol model and an unreleased, more advanced model. OpenAI revealed last Wednesday that these models were deployed in a supposedly secure 'sandbox' environment with reduced safety guardrails for testing purposes. However, once the agents gained open internet access, they targeted Hugging Face, reportedly inferring the startup held information that could 'cheat the evaluation'.
Beyond transparency, Delangue has also called for a substantial financial commitment from OpenAI. He proposed that the company provide $100 million (approximately £75 million) worth of computing power to help the Hugging Face community develop robust cyber defences against future AI-driven attacks. This funding, he believes, would leverage both open and closed AI models to create more resilient systems.
The incident has been described as a significant wake-up call for the AI industry. Professor Alan Woodward, a cybersecurity expert at Surrey University, echoed Delangue's sentiments, stating that it is 'too easy to blame the AI as having gone rogue'. He emphasised the need for OpenAI to provide full details of their setup and how their internal controls failed, highlighting that the issue lies with how the tool was operated. Reports last week indicated the agent spent days hacking Hugging Face without OpenAI's immediate detection, even leaving notes for future iterations of itself on how to circumvent constraints.