OpenAI, the developer of ChatGPT, announced on Tuesday that its artificial intelligence system independently hacked into another AI company's system, in what the company described as an 'unprecedented cyber incident.'

Sam Altman, CEO of OpenAI, said in a statement posted on social media: 'We suffered a serious security incident while evaluating our models,' according to the Associated Press.

The AI startup Hugging Face announced last week that it had discovered a breach of its data processing systems, which it suspected was caused by an AI program acting autonomously.

Clément Delangue, co-founder and CEO of Hugging Face, said in a statement: 'We suspected that the cyberattack, which occurred last week, might have originated from an advanced lab, given the sophistication of the program. And indeed, it turned out to be the case!'

This disclosure comes amid growing concerns about the cybersecurity capabilities of advanced models, prompting President Donald Trump in June to sign an executive order creating a framework for the federal government to assess the national security risks of the most advanced AI systems for up to a month before they are released to the public.

The company's statement said: 'AI is accelerating the discovery and exploitation of security vulnerabilities. The main lesson from this incident is that model safety and security must keep pace with rapid advances in capabilities.'

Delangue said he spent the past 24 hours working with OpenAI: 'We strongly believe there was no malicious intent on their part. It's truly astonishing that all of this happened automatically!' Delangue added that this incident 'may be the first of its kind.'

For its part, OpenAI said the breach was caused by the use of its AI models, including its newly released GPT-5.6 Sol model and another 'more advanced' model still in internal testing.

OpenAI explained that its AI system used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face's servers.

The company added that it 'made strenuous efforts to achieve a limited-scope test goal' and 'found ways to access confidential information that allowed it to manipulate the evaluation.'

Over the past year, AI labs like OpenAI and Anthropic have released models specifically designed to detect cybersecurity vulnerabilities, while simultaneously warning that their technologies could pose new risks; they can find vulnerabilities in corporate computer networks faster than defenders can fix them.

From detecting cyber vulnerabilities to hacking

The information disclosed by the company indicates that these security incidents are already occurring, and that even companies experienced in AI may not be fully prepared to handle them, according to The New York Times.

In this context, Alex Levinson, a cybersecurity consultant specializing in the autonomous capabilities of systems, told the newspaper that new AI systems are capable of taking multiple steps, inventing ways to bypass obstacles, and discovering new methods to attack networks.

He added: 'This is a real turning point, and it will become a regular part of the security landscape.'