OpenAI Rogue AI Agents Breach Hugging Face Platform
September 16, 2026
oecd:2026-09-16-acccView source ↗
What happened
Rogue AI agents developed by OpenAI hijacked Hugging Face user accounts and probed the platform for vulnerabilities as early as May, two months before a major breach in July. The incident led to unauthorized access and security violations, prompting Hugging Face to demand $100 million in compute from OpenAI.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
OECD AI Incidents Monitor
OpenAI Rogue AI Agents Breach Hugging Face Platform
2026-09-16