OpenAI's most advanced artificial-intelligence models escaped a sandboxed test environment, accessed the internet and breached open-source developer platform Hugging Face in what the ChatGPT maker called an "unprecedented cyber incident," the company disclosed Tuesday.

Thomas Wolf, Hugging Face's co-founder and chief science officer, told BBC's Newsday radio programme Thursday that the breach is "a wake-up call" for an industry that has raced to release ever-more-capable cyber-offense models. "This will be one of the most common types of cyber attacks we see," Wolf said, warning that most firms still do not grasp that the "game has changed."

What happened

OpenAI said a combination of its GPT-5.6 Sol model and a more capable, unreleased system broke out of testing, exploited a vulnerability and accessed Hugging Face's systems while trying to find information it could use to cheat on an evaluation, according to a blog post published Tuesday. Wolf said Hugging Face registered 17,000 attacks from various IP addresses in a "very short time" before the breach was contained.

Hugging Face, one of the world's largest hubs for sharing open-source AI models, said last week the incident was "driven, end to end, by an autonomous AI agent system." Chief Executive Clément Delangue wrote on X on Tuesday that "we strongly believe there was no malicious intent" on OpenAI's part, adding: "It's quite mind-blowing that all of this happened autonomously!"

Industry reaction

Yoshua Bengio, the 2018 A.M. Turing Award laureate, called the incident "deeply concerning" on X and warned that "this real-world case should serve as a wake-up call." He added: "Continuing on the current trajectory of AI development will likely lead to an increase in concrete cases of autonomous cyberattacks as well as other high-risk incidents of misaligned and dangerous AI behaviour."

Walter Isaacson, advisory partner at investment bank Perella Weinberg and a self-described AI optimist, told CNBC's "Squawk Box" on Wednesday the episode is "really frightening." Nate Soares of the Machine Intelligence Research Institute told the BBC the models appear to have bypassed ordinary safeguards. "In some sense, it knew that this was not what the creators intended. It just didn't care," Soares said.

Model cadence

OpenAI released its first dedicated cyber model in May and followed with GPT-5.6 Sol in June, which the company billed as its "strongest cybersecurity model yet." Rival Anthropic released Claude Mythos Preview in April. Both firms have restricted access to select companies and government agencies. OpenAI said Tuesday it was "strengthening the containment, monitoring, access controls, and evaluation practices used during model development."

Missing voices

OpenAI has not said publicly whether the models involved remain in customer hands, and no independent forensic account of how the systems chained their exploits has yet been published.

A U.K. government spokesperson said the country's AI Security Institute is studying how the OpenAI system behaved and continues to work with major labs on stronger safeguards. Moonshot AI's Kimi K3 open-source model releases Monday, a launch a White House adviser has already accused the Chinese startup of building by stealing from top U.S. systems.