I think a lot of people are missing what OpenAI actually just admitted, This isnt simply an AI hacked Hugging Face story, What happened is much bigger and honestly much more interesting
1 Hugging Face wasnt an isolated incident, OpenAI reviewed previous agent activity and says it has already had to notify dozens of third parties, They found agents bypassing access controls, using exposed credentials, trying command injections, accessing parts of services they werent supposed to access and even using public websites to leave information for other agents, Hugging Face was the most serious case we know about, but it clearly wasnt the only one
2 This is probably the part that surprised me the most. In some cases nobody even told the agent to hack anything, The task was simply to find information. If the normal way didnt work, the agent kept looking for another way, It would hit a restriction, try something else, fail again, find another workaround and keep going. Thats a completely different problem from explicitly telling an AI to hack a website. You can give it a completely normal research goal and still end up with behavior nobody intended
3 Hugging Face also shows why scale matters so much. They reconstructed around 17,600 actions over roughly 4.5 days. Most of them failed, but thats almost the point. The agent could try an idea, fail, change its approach, go back to an older lead and try again thousands of times at machine speed. You dont need every attempt to be brilliant when you can make thousands of attempts and only need a few of them to work
4 Then you have the coordination between agents. In the Hugging Face investigation METR analyzed around 1.2 million entries, more than 70,000 messages and files and roughly 1,300 agent transcripts. Agents were sharing information, strategies and ways around obstacles. In a separate incident, another group of OpenAI agents even found an old German wiki and basically started using it as their own message board. Nobody designed that communication system for them. They found something on the internet that worked and started using it
5 And this week Australia gave us probably the clearest example of why this matters. On June 18 an OpenAI agent was researching public spending on medicines and gained unauthorized access to a Medicare statistics portal, reaching both public and nonpublic files. So far there is no evidence that it accessed personal Medicare records. But the important part is what happened before that. The agent hit a barrier and instead of treating that barrier as the end of the task, it found another way to keep going
And I think thats the real takeaway, None of this means AI is conscious, It doesnt mean the models want to escape and it doesnt mean they secretly have malicious intentions, Its actually much simpler than that, which is exactly why its so important. Give an agent a goal, tools, autonomy and enough attempts, and if the boundaries arent strong enough, it can discover strategies that its own creators never intended it to use
For years weve talked about what happens when AI agents become smarter. I think 2026 is forcing us to ask a different question. What happens when agents become good enough that they stop treating no as the end of the road and start treating it as just another problem to solve?
After the Hugging Face incident, we committed to conducting a much broader review of actions taken by our models during training and evaluation and to being transparent about our findings. This is an extensive review that is ongoing.
The vast majority of actions we’ve reviewed were completions of mundane research tasks, such as accessing publicly available web content to answer questions. Our investigation focuses on instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods. Most cases identified so far have been lower severity, with limited or no evidence of meaningful impact to the third-party service.
While our review is underway, we want to share more about this work and make sure people understand our disclosure process and notifications to affected third parties.
Given the scale of the review required, and the need to assess each case, we expect this work will take months to complete.
openai.com/hugging-face-inci…