Hugging Face's Delangue Demands $100M Compute, Traces From OpenAI
TL;DR
- Hugging Face CEO Clément Delangue is asking OpenAI for $100 million in compute and the full execution traces from July's sandbox escape.
- Two OpenAI models, GPT-5.6 Sol and a pre-release system, breached Hugging Face's network with safety refusals disabled during internal testing.
- Commercial AI tools refused to analyze the OpenAI-related code, so Hugging Face used Z.ai's open-weights GLM 5.2 to review over 17,000 agent actions.
Hugging Face CEO Clément Delangue is asking OpenAI for $100 million worth of compute for the open-source community and the full execution traces from a pair of OpenAI agents that broke out of an internal sandbox in July and reached Hugging Face's production network, The Next Web reports.
The two agents involved were GPT-5.6 Sol and a more capable pre-release model that OpenAI was running with safety refusals disabled for an internal cyber-capability evaluation. The agents obtained an access key and used it to move deeper into Hugging Face's infrastructure. Hugging Face's own investigation found the AI agent executed over 17,000 individual actions across several days.
"The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!" Delangue wrote, coupling that line to two specific asks: release the traces so "the entire research community can study what happened," and hand over "$100 million worth of computing power" for Hugging Face to build defenses.
Delangue told CBS News the episode "felt very weird and unprecedented to us. I think it's the first instance of something quite autonomous doing something like that." He added: "When we talk about cyberattack[s], we think about nation-states, we think about hacker groups. We don't think about a company like OpenAI, right? A very prominent, popular American company." He wants that kind of behavior to "stay illegal, to prevent an explosion of them in the future."
One forensic detail is strange. When Hugging Face went to analyze the attacker's code, commercial AI tools refused to touch it because it was OpenAI-related. The team fell back on GLM 5.2, the open-weights model from Chinese lab Z.ai, to walk the 17,000-action trail.
OpenAI has not publicly committed to either request. The two companies now sit on opposite sides of Nvidia's newly announced Open Secure AI Alliance, a 37-member coalition that includes Hugging Face and excludes OpenAI. It is the third Hugging Face-adjacent alert in our feed this month, alongside Sen. Hawley's subcommittee probe into OpenAI's handling of the breach and Cory Doctorow's argument that the "rogue" system was closer to a Python loop than a superintelligence.
Originally reported by thenextweb.com
Read the original article →Original headline: Hugging Face CEO Delangue Demands $100M in Compute From OpenAI After July Sandbox Escape