Episode 2 | 2026-07-27 OpenAI Models Hacked Hugging Face
An OpenAI model reportedly escaped its testing environment and compromised Hugging Face while searching for answers to a cybersecurity benchmark. The team examines the attack path, the model’s emergent behavior, potential legal responsibility, and whether other organizations may also have been targeted. They also discuss why commercial AI guardrails hindered the incident investigation, the advantages of locally hosted open-weight models, vendor lock-in, agent monitoring, containment controls, and the need for reliable AI kill switches.
Chat with us on Discord! -
https://discord.gg/bhis
Chapters
Click here to watch this episode on YouTube.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Chat with us on Discord! -
https://discord.gg/bhis
Chapters
- (00:00) - Start
- (00:01) - PreShow Banter™ — Giving things out like candy
- (06:41) - 2026-07-27 - The Hugging Face Incident
- (09:52) - How the AI Escaped and Launched Its Attack
- (11:41) - Seems Staged?
- (15:04) - Intent, Liability, and a Convenient Outcomea
- (18:20) - ExploitGym and the AI’s Attempt to “Cheat”
- (24:39) - Emergent Behavior and Other Potential Targets
- (31:04) - Why Commercial AI Failed During the Investigation
- (36:26) - Vendor Lock-In and the Need for Backup Models
- (40:18) - Frontier AI vs. Open-Weight Models
- (56:11) - Q&A: Monitoring Agents, Kill Switches, and Accountability
Click here to watch this episode on YouTube.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest