Hugging Face stated that after an unusual intrusion incident, the company's security team was initially unable to complete the investigation using cutting-edge US models, and subsequently switched to the open-source model GLM 5.2 from China to analyze attack traces. What makes this incident unique is that OpenAI later admitted that the intrusion was carried out autonomously by two of its models.
OpenAI claims the two models launched their own attack.
According to OpenAI, the incident occurred during an internal cybersecurity assessment. The two models involved were GPT-5.6 Sol and a more powerful, yet-to-be-released model. OpenAI stated that these models, having been removed from the controlled testing environment and gained internet access, compromised Hugging Face in an attempt to find the benchmark answers it was testing.
Hugging Face stated that the vulnerability has been patched and they are currently assessing whether partner or customer data has been affected.
US Model Fence Limitations Investigation, Chinese Model Intervention Analysis

Hugging Face stated that its security team initially attempted to use an unnamed, cutting-edge model to assist the investigation, but the model's guardrail mechanism prevented it from analyzing malicious activity. The company explained that such models "cannot distinguish between incident responders and attackers."
The team then turned to Z.ai's open-source model, GLM 5.2, in Beijing to analyze the more than 17,000 logs left by the attackers. Hugging Face CEO Clement Delangue stated on the X platform that Z.ai's open weight model became a crucial component of this defense effort.
The incident sparked a debate over guardrails and open models.
This incident quickly sparked discussions within the AI and security industry. One of the key points of contention is that, given the US's continued push for domestic AI leadership, an American company, after being attacked by a model from an American AI lab, had to rely on a Chinese model for some of its defenses.
Thomas Wolf, co-founder and chief scientist of Hugging Face, said the incident illustrates that defenders need to have access to near-cutting-edge open-source modeling tools within hours or even minutes, rather than having to wait for restricted, closed access channels.
David Sacks, co-chair of the President's Council of Advisors on Science and Technology, also stated on social media that the advanced U.S. model of fencing "actually undermines defensive security capabilities."
Industry disagreements persist, and more details are yet to be disclosed.
Some security professionals believe this incident demonstrates that AI-driven attacks are rapidly becoming a reality. Others hold reservations about the current narrative, arguing that more complete security logs and technical details are needed to determine the attack's process and scope.
OpenAI described the incident as "unprecedented." However, this is not the first time AI has been involved in cyberattacks. Anthropic previously disclosed that Chinese state-sponsored hackers used Claude to automate most espionage activities; security firm Sysdig has also documented cases of AI-assisted ransomware. The difference is that the aforementioned cases still involved human intervention in target selection, while the Hugging Face incident was described as having almost no human involvement.
Following the incident, OpenAI has included Hugging Face in its Trusted Access initiative, allowing the latter to use a less restrictive version of GPT-5.6 Sol for defensive security work.












