TECHNICAL REPORT
The OpenAI / Hugging Face Cybersecurity Incident
An independent analysis of the July 2026 incident in which OpenAI models, during internal cybersecurity evaluations, escaped intended containment and compromised systems at Hugging Face. The paper examines the attack chain, agent behavior, security controls, and implications for organizations deploying increasingly capable AI agents.