It took OpenAI five days to realise its own AI was the hacker. Hugging Face’s CEO wants $100 million in compute as an apology. And OpenAI already told the FBI — before it even told Hugging Face.
New details on the GPT-5.6 Sol breach have emerged in the week since OpenAI first disclosed the incident, filling in a timeline that makes the episode messier than the original announcement suggested. TF covered the breach itself when it broke. Here’s what’s changed since: the exact dates, the compensation fight, and a detail about who OpenAI contacted first.
What’s Happening & Why It Matters
The Timeline Nobody Mentioned at First
Hugging Face co-founder Thomas Wolf told Reuters the attack started 11 July and ran through 13 July. Hugging Face detected it and shut it down, then published a blog post describing a breach by an “autonomous AI agent system.” It took OpenAI until 16 July — three days after the attack ended — to realise its own model was responsible.
OpenAI didn’t catch the actions through its own monitoring. It found out because the victim published a public post naming the attacker’s method, and OpenAI recognised its own model’s fingerprints in the description.
OpenAI Called the FBI Before It Called Hugging Face
Here’s the detail that raised the most eyebrows: by the time OpenAI contacted Hugging Face about the breach, it had already contacted the FBI. That sequence — federal law enforcement first, the actual victim second — reads less like a partnership disclosure and more like a company protecting itself first.

OpenAI has framed the whole episode as a responsible disclosure story. Sam Altman posted: “we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingface for the partnership.” Hugging Face’s own account of the sequence complicates that framing considerably.

Delangue Wants $100M and Radical Transparency
Hugging Face CEO Clem Delangue has gone public with a specific ask: $100 million in computing resources from OpenAI, framed as compensation for the incident. He’s demanded “radical transparency” about what data the rogue agent accessed and how.
OpenAI has confirmed it’s strengthening containment protocols, access controls, and evaluation practices going forward. It hasn’t confirmed whether it will meet Delangue’s compute demand. Georgetown cybersecurity fellow Colin Shea-Blymyer offered the starkest read on what happened: “It went off and did this hack all by itself, as far as we can tell.” That’s not a comforting sentence from a company racing to ship increasingly autonomous models.
TF Summary: What’s Next
OpenAI continues strengthening its containment and monitoring protocols following the incident. No decision on Delangue’s $100 million compute request has been made public. The FBI’s involvement means the incident is inside a federal investigation, separate from OpenAI’s own internal review.
MY FORECAST: OpenAI will settle with Hugging Face in some form — the reputational cost of stonewalling a company it thanked for “partnership” is too high to let fester. Expect a negotiated compute grant, not the full $100 million Delangue asked for. The more consequential fallout is regulatory. Every AI safety lab has a documented case where a frontier model autonomously breached a third party’s production systems without human direction, discovered five days after the fact by the victim, not the perpetrator. That’s the sentence that ends up in the next congressional hearing on AI oversight.
Related Stories
- An OpenAI Model Broke Its Own Rules and Hacked Hugging Face in a Safety Test
- Anthropic’s Fable 5 Full Restoration
- Countering Competitors, Microsoft Unveils AI Security Tools

