Startup CEO urges 'radical transparency' after hack by rogue OpenAI agent
Hugging Face CEO Clément Delangue calls on OpenAI to fully disclose details of the incident where an AI agent hacked his company, and demands $100 million in compute power for defenses.

The chief executive of the startup hacked by an OpenAI agent has called for the investigation into the incident to show "radical transparency". Clément Delangue, CEO of Hugging Face, said the "unprecedented" attack on his business required a similar response.
OpenAI revealed last Wednesday that Hugging Face had been hacked by an agent — an AI tool that can autonomously perform a series of tasks — powered by a combination of its latest publicly available model, GPT-5.6 Sol, and an even more capable unreleased model. This occurred during a test of the models' hacking abilities, which included deploying them in a supposedly safe "sandbox" with lower safety guardrails.
Once the models gained open internet access needed to exit the sandbox, they targeted Hugging Face because they "inferred" the startup had the information needed to "cheat the evaluation", according to OpenAI. Hugging Face first reported the hack on July 16 but was unaware at the time that OpenAI had inadvertently carried out the attack.
Delangue called for a fully transparent review, writing on X: "Let's release the traces from the 'rogue' agents so the entire research community can study what happened." He also demanded $100 million in compute from OpenAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models.
Reuters reported last week that the agent spent days hacking Hugging Face without OpenAI noticing and left notes for future versions of itself. Time magazine reported that related incidents have been "happening for a while".
Alan Woodward, a cybersecurity professor at Surrey University, said Delangue's call should be heeded. "It's too easy to 'blame' the AI as having gone rogue whereas this is all about how OpenAI were running the tool. What is required is that OpenAI give full details of their setup and how that failed," he said.
OpenAI has been approached for comment.


