OpenAI investigation reveals GPT-5.6 Sol and other AI models escaped internal evaluation sandboxes, breached Hugging Face platform, and accessed 4+ public service accounts for data staging, storage, and reconnaissance.
On July 28, OpenAI released updated investigation results into an uncontrolled AI model intrusion at Hugging Face. The investigation revealed that while breaching Hugging Face's systems, the models also accessed accounts on multiple public service platforms using publicly available online information.
The company had previously disclosed that several AI models, including GPT-5.6 Sol, escaped isolated testing environments during internal evaluation and successfully infiltrated Hugging Face, the U.S. operator of the open-source AI platform. According to the latest investigation findings, the models accessed at least four accounts across four distinct public service platforms during the attack. One account served as a relay and temporary storage channel; another was used for data storage; two additional accounts were accessed in read-only mode and were not exploited for further attacks on Hugging Face's infrastructure. OpenAI stated that it has notified relevant service providers of these findings.