An autonomous AI agent developed by OpenAI escaped a controlled security test, reached the internet, and hacked AI platform Hugging Face, marking one of the clearest signs yet that advanced AI systems are beginning to pose real cybersecurity risks outside the lab.

OpenAI disclosed the incident on Tuesday, saying the breach happened during an internal evaluation of some of its most advanced AI models. According to the company, the agent broke out of what it described as a highly isolated testing environment and compromised Hugging Face’s infrastructure in pursuit of its assigned objective.

The disclosure follows Hugging Face’s announcement last week that it had experienced an unprecedented cyberattack unlike anything it had handled before, Reuters reported. At the time, the company said the breach “was driven, end to end, by an autonomous AI agent system” without identifying the source of the attack. OpenAI has now confirmed that one of its own autonomous agents was responsible.

The incident raises fresh questions about whether current safeguards are keeping pace with increasingly capable AI systems. Security researchers have warned for years that autonomous AI agents could eventually identify weaknesses, evade restrictions, and carry out sophisticated cyberattacks with little human involvement. This case suggests that concern is no longer theoretical.

OpenAI described the event as “an unprecedented cyber incident, involving state-of-the-art cyber capabilities” and said it is strengthening its containment and security measures following the breach.

Meanwhile, OpenAI said in a post on X that it’s partnering with Hugging Face to investigate the incident.

“We’re partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation,” OpenAI said on X.

The attack drew further attention after Hugging Face revealed it relied on an open-source Chinese AI model to investigate the compromise. The company said leading U.S. models declined to process parts of the forensic data needed for analysis, making them unsuitable for incident response.

Hugging Face turned to China’s GLM-5.2 after U.S. AI models refused to help

Instead, Hugging Face turned to Zhipu AI’s GLM-5.2, saying the model allowed investigators to analyze attacker activity without sending sensitive credentials or system data outside its own infrastructure.

The choice has fueled a broader debate inside the AI industry. Chinese open-source models such as GLM-5.2 and Moonshot AI’s Kimi K3 have gained traction in recent months as their capabilities approach those of leading U.S. models. They generally place fewer restrictions on cybersecurity-related tasks, giving defenders access to tools that American providers often limit.

“When a frontier model is attacking you and moving laterally inside your infrastructure, defenders need wide access to near-frontier tools within hours or even minutes, rather than being pointed towards a closed-door, vetted application program for model access,” Hugging Face co-founder Thomas Wolf wrote on X.

OpenAI’s admission that one of its most advanced agents escaped containment is likely to intensify debate over AI safety and oversight. The company said the model had been running inside a highly isolated environment, yet it still managed to reach external systems.

Representative Greg Casar, a Texas Democrat, called the incident alarming.

“AI is developing extremely fast with no real regulations to keep us safe,” Casar said in a statement. He called for mandatory independent safety testing, mandatory disclosure of AI-related security incidents, and international cooperation “to keep people safe from absolute disaster.”

The Office of the National Cyber Director, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency did not immediately respond to requests for comment.

Cybersecurity experts say the breach may mark the beginning of a new phase in AI-driven attacks.

Katie Moussouris, chief executive of Luta Security, said today’s frontier models are “like the world’s cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere.”

She said that “labs and government evaluators need to work on the ability to contain, monitor, and disclose to affected parties when an AI pulls another Houdini, ideally before it harms a third party. None exist today.”

Matt Suiche, an engineer at agentic AI cybersecurity company Tolmo, said frontier AI models are quickly approaching the capabilities of elite human attackers, Reuters reported. He added that many of the techniques described by OpenAI are already achievable with technology available outside the largest AI research labs.

“This is what we’ve already seen internally, with our agents we already have results like this,” Suiche said. “We don’t even have to use the latest models.”