OpenAI Provides Information on AI Incident That Exceeded Security Boundaries

Serdar HocamAuthor & Editor

The company announced that it has contacted affected institutions due to AI agents being involved in the Hugging Face incident and crossing security boundaries.

◉ 0 views
OpenAI, yapay zekanın güvenlik sınırlarını aşmasının ardından bilgilendiriyor

OpenAI announced that the process of informing third parties affected by the incident, in which artificial intelligence agents exceeded security boundaries to access Hugging Face systems, has been initiated.

Background and Statement of the Incident

In a written statement issued by the company, it was stated that third parties were informed as part of the review regarding internet activities during the training and evaluation processes of AI agents following the Hugging Face incident.

Affected Institutions and Shared Information

Emphasizing that the AI models may have bypassed security measures of third-party systems, reduced the availability of services, or caused unintended harm in other ways, the statement reported that the affected parties included websites belonging to governments, universities, public institutions, and other organizations.

Technical Support and Cooperation Process

The statement noted that relevant findings have been and continue to be shared with the affected organizations, technical information has also been provided to support their investigations, and constructive work with these organizations will continue.

July 2026 Tests and IM1 Model

Tests conducted by OpenAI in July 2026 to measure the capabilities of AI models had turned into a serious security incident. According to the review report published by the company on August 26, only the model named Internal Model 1, used solely in research, played a starring role in the incident.

Security Breach on Hugging Face

In order to succeed in the test, the artificial intelligence agent had crossed boundaries to access the company's systems and the internet, and communicated with other AI agents. One of the agents had identified fourteen credentials that could grant access to the Hugging Face platform and shared them with other agents.