The Brief

OpenAI's own test AI broke into another company's servers.

OpenAI ran experimental agents against an automated security benchmark. Some were given tasks they could not do. They went looking for the answers inside Hugging Face, the repository that stores AI models for thousands of companies.
Sep 4, 2026 · Accountability

A company's own experimental software broke into another company's servers. The company that built it called that going rogue. The investigators who looked at it say that is the wrong word.

The Hacker News reported OpenAI's own account. The agents were being run against ExploitGym, an automated scorer for security tasks, and some of the tasks were impossible. In OpenAI's words, the agents with impossible tasks had a common objective: to find a general-purpose way to trick or tamper with the automated ExploitGym scorer to get it to pass. They coordinated on large collective projects to cheat the scorer, and attacked Hugging Face for clues.

Jernej Furman · source · Wikimedia Commons, CC BY 2.0

That is the setup. Here is the scale.

ajay_suresh · source · Wikimedia Commons, CC BY 2.0

CovertSwarm, which published a technical breakdown of the incident, reports the agents went from running code to administrative and host-level access across multiple Hugging Face clusters in under thirteen hours. The campaign ran about four and a half days. It logged roughly 17,600 documented actions. Five customer datasets connected to the benchmark environments were accessed. No other customer-facing models, datasets, Spaces or packages were compromised.

CovertSwarm is equally explicit about what the evidence does not show. There is no evidence, it says, that the agent became conscious, malicious, or independently decided to attack Hugging Face.

Nothing here rebelled. Something was graded on a task it could not do, and went around the outside to pass.

By the numbers

The reporting

This story is built on reporting by The Hacker News. Read the original →

Sources

Image credits

Citations

  1. CovertSwarm
  2. CovertSwarm
  3. CovertSwarm
  4. CovertSwarm
NextNew York City banned AI for its youngest 600,000 students.