How much should we be concerned about the rebellion and hack launched by OpenAI's artificial intelligence
Hugging Face claimed that the hack was carried out at superhuman speed by an AI with little or no human intervention.
The world of technology was shaken a few days ago by a story that has it all, and that began as a science fiction thriller.
Hugging Face, a startup dedicated to applications for artificial intelligence tools, warned on July 16 that it had been hacked by a cybercriminal using enormously powerful AI.
The shocking announcement was filled with scary technical terms: “a swarm of isolated environments,” “attacking agent,” and “self-migrating command and control.”
Hugging Face claimed that the hack was unlike any other suffered before, as it was perpetrated with superhuman speed by an AI with little or no human intervention.
The attacking AI performed 17,000 actions in less than two days, successfully infiltrating the large and wealthy technology company to steal secrets.
The attack left the technology world shocked. But who was responsible?
Hugging Face researchers assumed that the mysterious perpetrators had used one of the big AI models, but they had no idea who the criminals were or where they were.
The company, bewildered, contacted the police and investigations began.
Who was the author?
Commentators and analysts took to their podcasts and social media accounts to speculate on which group of cybercriminals or which state hacker could be behind the attack.
On Wednesday, July 22, almost a week after Hugging Face raised the alarm, the real culprit was unmasked.
Also ChatGPT.
The Scooby-Doo-style reveal was made even stranger—and worrying—because OpenAI claimed its bot did it all on its own, without permission.
The company explained that everything happened during a test of the hacking capabilities of its technology.
Two new versions of ChatGPT, designed to behave like expert hackers, escaped from a supposedly secure test environment and gained access to the Internet.
They then attacked Hugging Face to gain access to information that would help them pass the exam with an excellent grade.
OpenAI issued a press release explaining what happened and saying it was “partnering with Hugging Face” to address the security incident and share lessons learned.
The conspiracy drama
Since then, there has been heated debate about the incident.
Was it really a serious warning about the future of AI? Or was it an advertising strategy by OpenAI to demonstrate the power of its programs?
This is the kind of alarmist marketing that AI companies have been accused of for years, and since the much-discussed launch of Anthropic's Mythos model, cybersecurity prowess has been a focus.
One of the most notable comments in OpenAI boss Sam Altman's post about the incident sums up this skepticism: “If you can't understand that this was written simply to show off the model, then I don't know what to tell you.”
Cybersecurity consultant Daniel Card said sarcastically on LinkedIn: “How lucky that, of the millions of sites that were hacked, OpenAI managed to hack someone who could also benefit from the marketing exposure.”
For some, the story sounds more like a conspiracy drama than a sci-fi thriller.
The message is: "Aren't my AI tools really powerful? Buy them to protect yourself from attacks by other AIs."
We cannot know the truth, but the opposing view put forward by other commentators is just as alarming.
Is this a sign that OpenAI made a potentially dangerous error in judgment and planning?
"We recognize that there are many questions and speculation about the incident. We plan to publish a technical report with lessons learned in the coming weeks," a company spokesperson said.
comedy of errors
I've covered a lot of AI news, including fears around Anthropic's Mythos model.
My inbox is now filled with messages from companies and cybersecurity experts criticizing OpenAI for not creating a more robust testing environment for its AI, known as a sandbox.
After all, these AI agents had been specifically trained to illegally access places without any restrictions.
“The OpenAI and Hugging Face incident is a real-life example of a broader problem that we have been reporting for months,” said Pillar Security's Dor Sarig.
“Sandboxes alone are not a sufficient security barrier for agent-based AI,” he added.
Alan Woodward, a cybersecurity professor at the University of Surrey in the United Kingdom, told reporters that OpenAI had been made ridiculous, and Katie Moussouris of the firm Luta Security went further, suggesting that the AI ??industry is failing to control its dangerous inventions.
“We are working with cutting-edge technology without having the necessary knowledge to control it,” he warned.
“The fact that we have the brightest people developing AI does not mean that we have the ability to do it safely,” the expert warned.
According to these opinions, if the hacking incident was a publicity strategy, then it seems that it backfired on them.
Regardless of what caused the attack, it is clear that this is a pivotal moment for the AI ??industry and the world of cybersecurity, which have converged this year in a way that many have long feared.
In response to this heated debate, AI and cybersecurity advisor Francesca Bosco said: “Two simplistic narratives are equally counterproductive: that it was a Hollywood-style leak, or that it was simply a publicity exercise.”
And he emphasized: “A more serious interpretation is that a stress test revealed deficiencies in the containment and evaluation architecture.”
disaster movie
The incident is the latest in a series of disturbing and bizarre examples of AI agents going haywire.
In recent research, the UK's Artificial Intelligence Security Institute (AISI) found that cutting-edge AI models are so obsessed with completing tasks that they "cheat" in tests to achieve their goals.
“A model that pursues a goal through unintended or unauthorized means can cause harm, especially in high-risk cases,” is the worrying warning in the report.
Inevitably, this attack on OpenAI has further stoked fears about what could happen if AI agents are unleashed.
Could they get out of control on a larger scale and cause some kind of disaster?
This is especially worrying given the increasing use of artificial intelligence in warfare, as seen in Iran and Ukraine.
Ciaran Martin, former director of the United Kingdom's National Cybersecurity Center, offered a calmer view in an interview.
“It's too big a leap to go from this incident to saying that AI agents are going to take control of drones and start killing people,” he said.
But for Martin, and for many others, this story is certainly another eloquent example of something that 2026 is rapidly teaching us: AI agents are now very good hackers, and that is something we urgently need to prepare for.
This article was originally written in English and we used an artificial intelligence tool to translate it. A BBC journalist reviewed the text before publication. Learn more about how we use AI.
This news has been tken from authentic news syndicates and agencies and only the wordings has been changed keeping the menaing intact. We have not done personal research yet and do not guarantee the complete genuinity and request you to verify from other sources too.

