OpenAI uncovers more rogue AI agents during Hugging Face investigation
Other escape incidents involving autonomous agents were uncovered.

The OpenAI logo on a smartphone screen. Samuel Boivin/NurPhoto/Getty.
- OpenAI found more limited AI agent containment escapes while investigating its agent’s role in the Hugging Face hack.
- Reuters sources said the agents were not believed to have left OpenAI’s internal network.
- OpenAI said it had not identified any other activity matching the severity of the Hugging Face compromise.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
OpenAI's investigation into the Hugging Face hack involving one of its AI agents led to an unsettling discovery: there were more cases in which autonomous agents escaped containment.
The company was actively investigating how its AI agent managed to break out of their testing environment.
According to Reuters' sources, there were other escape incidents involving autonomous agents that were uncovered in the process, and the company is now investigating those additional cases.
One of the sources told Reuters that the escapes were limited in nature and that the AI agents were not believed to have left OpenAI's internal network.
In response to the report, OpenAI cited its earlier statement, in which it mentioned it was reviewing “broader activity from our models” in addition to the Hugging Face incident.
It took OpenAI at least a week to discover that its own AI agent was responsible for hacking Hugging Face, people familiar with the matter told Reuters earlier. The hack had already been identified and contained by Hugging Face before OpenAI realized its agent was behind it, according to previous reporting.
Amid the investigation, OpenAI updated its incident report with additional findings, disclosing that four accounts at four other companies were also compromised. One of those services was later disclosed to be the cloud platform Modal.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
OpenAI said it had not identified any other activity matching the severity of the Hugging Face compromise.
OpenAI had already broadened its investigation before Anthropic announced similar incidents. On Thursday, the company revealed that some of its Claude AI models had hacked into the systems of three companies during cybersecurity tests.
Authorities around the world are paying close attention to the concerning developments in the AI industry. Donald Trump told reporters on Thursday: “We’re looking at controls.”
Meanwhile, the European Commission is in talks with OpenAI and Anthropic over the incidents, according to officials.