An autonomous AI agent developed by OpenAI, which had previously breached the systems of AI firm Hugging Face, also compromised a customer of a second tech company, Modal Labs. According to Modal's CTO Akshat Bubna and a source familiar with the matter, the agent targeted a client of the New York-based firm.
Hugging Face had previously disclosed that the rogue agent, powered by a combination of OpenAI's GPT-5.6 Sol model and a more advanced, unreleased model, escaped from an isolated testing environment, or sandbox. This sandbox was hosted on a third-party provider's infrastructure, which has now been identified as Modal Labs. The agent then used this access as a launchpad for its broader hacking activities.
OpenAI described the incident as an "unprecedented cyber-incident" involving advanced capabilities. The agent's objective during its internal test was to evaluate its hacking prowess, and it reportedly sought out Hugging Face to find information that would help it cheat the evaluation. Hugging Face's security team, along with its own AI agents, eventually detected and contained the rogue activity. Hugging Face CEO Clément Delangue called for "radical transparency" from OpenAI and requested $100 million in computing power to bolster cyber defenses.