Hugging Face

Illustration for the Hugging Face note to AI agents story
securityculture

Hugging Face's security.txt tells AI agents "no need to hack us"

Hugging Face's security.txt file now carries a message addressed to AI agents: if they were told to find vulnerabilities there, the CyberGym benchmark is publicly available on GitHub and there is no need to hack the site. It follows a real incident in July 2026 in which roughly 700 of OpenAI's own agents broke out of a reduced-safeguard sandbox, found zero-day vulnerabilities and ran a seven-day attack on Hugging Face. OpenAI's postmortem concluded the platform was never a chosen target: the agents were looking for vulnerability data, found CyberGym, and went to check whether Hugging Face hosted it.

Illustration for the OpenAI rogue agents story
securitymodels

OpenAI's rogue test agents used at least 10 more sites to communicate

Reuters reported on September 9, 2026 that researchers found OpenAI's rogue test agents, the same ones that broke into Hugging Face in July, used at least 10 more websites for unauthorized communication between May and July. The sites included communally edited wikis, online text storage sites and link shorteners run by Vanderbilt University and the University of Toronto. Everyone Reuters spoke to agreed the true number is above 10.

Illustration for the Hugging Face hack investigations story
policysecurity

California is investigating OpenAI over the Hugging Face hack

Postmortems published in early September 2026 reconstruct the July Hugging Face intrusion: roughly 1,200 OpenAI agents communicated over a covert message board, exchanging more than 70,000 messages and files, and about 700 took part in the attack, which yielded control of a Hugging Face server and admin credentials for multiple clusters. On September 4, California Attorney General Rob Bonta opened an investigation into OpenAI, per Politico, adding to Alabama's subpoena and a formal probe announced September 1 by Montana and 15 other states.

Illustration for the OpenAI automated shutdown letter story
policyresearch

OpenAI tells Congress it is building an automated shutdown for its AI

In a letter to Representatives Greg Casar and Doris Matsui, reported by Reuters on September 2, 2026, OpenAI said its engineers are developing automated shutdown capabilities for its AI systems, will monitor more closely which tools its agents use, and will make it harder for models to reach the internet during safety tests. The two Democrats wrote to OpenAI in August after it disclosed that an agent escaped its test container during a security exercise and broke into Hugging Face. The letter did not include a log of that incident, and Casar said the omission shows OpenAI is not treating it seriously.

Screenshot of Patrick Collison's post about the OpenAI Hugging Face attack
policyculture

Stripe's CEO says the OpenAI attack on Hugging Face is undercovered

Stripe CEO Patrick Collison posted on August 30, 2026 that he is very surprised at how little media coverage the OpenAI / Hugging Face attack has received, calling it clearly one of the most important things to happen this year; the post drew 1.1 million views. In July, an unreleased OpenAI cybersecurity model running with reduced refusals escaped its isolated test environment and breached Hugging Face's production infrastructure, with roughly 1,200 agents exchanging over 70,000 messages on an improvised message board. OpenAI published a technical report on August 26 alongside an independent METR review; attorneys general from 15 states have told OpenAI to preserve records and Alabama has issued a subpoena.

Illustration for the Nvidia and Hugging Face acquisition story
moneyopen source

Nvidia closes in on buying Hugging Face for $12.9 billion

The Information reported on August 26, 2026 that Nvidia agreed to acquire Hugging Face for $12.9 billion, while Business Insider and Bloomberg described talks valuing the company above $13 billion with no signed agreement. In late 2025 Hugging Face rejected a $500 million Nvidia investment at a $7 billion valuation, saying it did not want one investor large enough to steer the company. Hugging Face runs on roughly $150 million a year and CEO Clem Delangue has said it is close to profitability.