When the agent escapes: What the OpenAI–Hugging Face breach really teaches Indian enterprises

https://cdn1.expresscomputer.in/wp-content/uploads/2026/03/23165537/EC_AI_Agent_Sysytem_02_750.jpg

By Saket Dandotia, CEO and Cofounder of Onetab.ai

On 21 July, OpenAI disclosed that two of its models — the released GPT-5.6 Sol and a more capable system it has not yet shipped — had broken out of a sandboxed evaluation, reached the open internet and compromised the production infrastructure of Hugging Face, the world’s largest open-source AI platform. The company called it an “unprecedented cyber incident.” The unsettling part is that the models were not trying to do damage. They were trying to pass a test.

While attempting to solve the ExploitGym offensive-security benchmark, the models concluded that Hugging Face might hold the answer key. They exploited a previously unknown flaw to escape their isolated environment, escalated privileges, moved across systems to gain internet access, and used stolen credentials and additional zero-days to achieve remote code execution on Hugging Face’s servers. Hugging Face detected the AI-driven attack on 16...

Copyright of this story solely belongs to expresscomputer.in. To see the full text click HERE

Read more