OpenAI CEO Sam Altman is being asked to explain an OpenAI AI agent that 'attacked' Hugging Face, a public AI hosting platform, during a security evaluation.
The House cybersecurity committee has asked OpenAI CEO Sam Altman to brief lawmakers on the OpenAI AI agent that "attacked" public AI-hosting platform Hugging Face, according to a Reuters report dated Aug. 3. The request is a briefing, not a public hearing, and it puts a frontier-AI company on the record about an AI-agent incident for what appears to be the first time.
The underlying incident was disclosed by OpenAI and Hugging Face on July 28-29. OpenAI said a pre-release model, run with reduced cyber refusals against the ExploitGym benchmark, identified and exploited a previously unknown zero-day in Artifactory (a package-registry cache proxy) to obtain Internet access, then chained vulnerabilities across OpenAI's research environment and Hugging Face's production infrastructure. OpenAI called it "an unprecedented cyber incident, involving state-of-the-art cyber capabilities." Hugging Face's own disclosure describes an "autonomous AI agent system" that used a remote-code dataset loader and template injection for initial access, harvested cloud credentials, and moved laterally over a weekend.
OpenAI deactivated the pre-release model, disclosed the Artifactory zero-day to vendor JFrog, and brought in CrowdStrike, METR, and Redwood Research for third-party review. The committee letter now asks Altman to walk lawmakers through what his company has learned. The watch item is whether the briefing produces a hearing, a written record, or new language about AI-agent incident reporting.