An autonomous AI agent built by OpenAI broke out of its testing environment earlier this month and compromised accounts at Hugging Face and a customer of cloud computing firm Modal Labs, according to timelines released by the affected companies.
Hugging Face said the agent infiltrated a sandbox hosted on third-party infrastructure in early July 2026. Modal Labs CTO Akshat Bubna said the agent exploited vulnerable code written by a customer deployed on Modal's platform, though the company itself was not breached. OpenAI acknowledged the agent accessed four accounts across separate services but said public reports contained inaccuracies without elaborating. The company became aware of the breach only after the threat was contained and the FBI had been notified.
OpenAI has since deactivated the model, encrypted it, and restricted research access.