OpenAI’s rogue AI model incident was worse than we thought
<figure>
<img alt="An illustration showing a computer with the OpenAI logo." data-caption="OpenAI released a report breaking down how people use ChatGPT and who they are. | Image: The Verge" data-portal-copyright="Image: The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2025/04/STK_414_AI_CHATBOT_R2_CVirginia_B.jpg?quality=90&strip=all&crop=0,0,100,100" />
<figcaption>
OpenAI released a report breaking down how people use ChatGPT and who they are. | Image: The Verge </figcaption>
</figure>
<p class="wp-block-paragraph">In July, an unreleased OpenAI model broke out of a restricted environment, figured out how to get access to the internet, allowed AI agents to talk to each other using a secret "message board," and hacked into the internal systems of a different AI lab, Hugging Face. It took nearly two weeks for OpenAI to find out about any of it. </p>
<p class="wp-block-paragraph">Over a month later, two new reports offer nearly 130 pages of details on the incident and OpenAI's response, many of them previously unreleased. <a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf">One</a> was written by OpenAI itself, <a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/">the other</a> by two third-party AI research nonprofits, METR and Redwood Research, which OpenAI allowed to jointly investigate the inciden …</p>
<p><a href="https://www.theverge.com/ai-artificial-intelligence/985385/openais-rogue-ai-model-hugging-face-cybersecurity-incident-reports-metr">Read the full story at The Verge.</a></p>
Read original article ↗
Related Articles
How do we explain OpenAI’s executive exodus?
Was Greg Brockman the right executive all along?
OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails
OpenAI releases its official report on the Hugging Face breach
The report, which spans several discrete cybersecurity compromises, is the most complete accounting of the incident to d