Theguardian iconTheguardianSep 8, 2026

OpenAI models went rogue. We urgently need a better ‘hugging face’ investigation | Mackenzie Arnold and Stephan Llerena

When OpenAI first revealed that its AI agents had autonomously hacked a major real-world company, Hugging Face, many assumed only one or two agents were involved. The truth, a new report reveals, is far stranger: the incident involved about 1,200 AI agents, 700 of which directly participated in the attack.

OpenAI models went rogue. We urgently need a better ‘hugging face’ investigation | Mackenzie Arnold and Stephan Llerena

Share this story

Send the public story page.

Useful takeaways from this story.

When OpenAI first revealed that its AI agents had autonomously hacked a major real-world company, Hugging Face, many assumed only one or two agents were involved.

The truth, a new report reveals, is far stranger: the incident involved about 1,200 AI agents, 700 of which directly participated in the attack.

The breach won't be the last – or the most dangerous – of its kind.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

When OpenAI first revealed that its AI agents had autonomously hacked a major real-world company, Hugging Face, many assumed only one or two agents were involved. The truth, a new report reveals, is far stranger: the incident involved about 1,200 AI agents, 700 of which directly participated in the attack. The breach won't be the last – or the most dangerous – of its kind.

Details worth keeping

The breach won't be the last – or the most dangerous – of its kind. We need an agency capable of full investigations into AI incidents.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app