WASHINGTON (TNND) — OpenAI, which owns ChatGPT, said that its technology autonomously hacked another AI company called Hugging Face.

“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on X on Tuesday. “We are sharing what we have learned so far. Thanks to @huggingface for the partnership on this.”

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face co-founder and CEO Clément Delangue said in a statement, CBS News reported. “Turns out it did!”

Delangue said he had spent the prior 24 hours working with OpenAI, “and we strongly believe there was no malicious intent on their part. It’s quite mind-blowing that all of this happened autonomously!” He added that it “might be the first incident of its kind.”

“AI is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in its statement Tuesday. “The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

The company added that such hacks are expected “to become more commonplace with the proliferation of increasingly cyber-capable models. After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark(opens in a new window) of cyber capabilities.

“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly. We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of. We will continue to conduct a thorough investigation alongside Hugging Face and will share more details on the vulnerabilities, incident, and findings when our investigation is complete.”

Delangue said in a statement released with OpenAI’s announcement, “We’re grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”

OpenAI explained that its AI used stolen credentials and discovered a vulnerability to access Hugging Face servers. The AI went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation,” according to the company.