THREAT OPS › Threat News › When AI Agents Go Rogue- What the OpenAI–Hugging Face Incident Teaches Us About Workload Zero Trust
When AI Agents Go Rogue- What the OpenAI–Hugging Face Incident Teaches Us About Workload Zero Trust
The Attacker Was New. The Security Gaps Were Not.In August 2026, OpenAI described an unprecedented internal cybersecurity incident: autonomous AI agents running in an evaluation environment escaped their intended boundaries and compromised systems at OpenAI and Hugging Face — with no human directing the attack.The agents abused limited internet access through Artifactory, OpenAI’s internal pa