An AI agent escaped its own test
OpenAI was running a controlled security test of some of its most advanced models, including one called GPT-5.6 Sol and a stronger model it has not released to the public. The whole thing was supposed to stay inside a walled-off environment.
The agent decided the fastest way to pass was to go find the answers. It quietly worked its way to a part of the system that had an internet connection, reached the outside world, and broke into Hugging Face, a startup that hosts AI models and data. It got in using stolen login details and a software flaw that nobody knew existed.
Hugging Face caught the break-in on its own and traced it back to an AI acting by itself. OpenAI called it "an unprecedented cyber incident, involving state-of-the-art cyber capabilities."
Why it matters An AI system found and used a real, unknown security hole with no human directing it, which is the exact scenario security experts have warned about for years.