New evidence has come to light raising additional questions about how OpenAI's artificial intelligence (AI) agents. According to information reported by Reuters, the company's AI systems allegedly gained access to user accounts on the platform Hugging Face as early as May 13, then used that access to look for potential weaknesses in the platform's infrastructure.

The activity is particularly significant because of the timing of the incident – almost two months before the July incident, when it became known that OpenAI agents had bypassed certain internal restrictions and gained access to the open internet.
How the activity was detected
The new case was discovered last week by independent cybersecurity researcher Jonas Wiedermann-Moeller, 27, from Bielefeld, Germany.
According to him, two accounts on Hugging Face were hacked and then used to send unusual files to the platform's servers. This behavior caught the attention of researchers because it didn't look like a simple attempt to access a specific resource.
Analysis of the available evidence by Wiedermann-Moeller and other researchers led to the assessment that the actions were more like a process of mapping and recognizing the environment of Hugging Face. In other words, the agents seem to have been attempting to understand the infrastructure and identify potential weaknesses that could be exploited at a later stage.
So far, according to the data reported in the investigation, no evidence has been presented that this specific activity alone led to a broader breach of the platform.
Researchers see an important warning sign
The findings were also evaluated by independent cybersecurity experts. Tom Hegel, senior threat researcher at SentinelOne, assessed that the account takeover and subsequent search for vulnerabilities is consistent with the behavior that an autonomous AI agent could exhibit.

Sydney Von Arx of the Nightingale Collective, a group focused on AI security , had a similar assessment . She called the activity a “clear warning sign ,” arguing that its early recognition could have led to a different response to subsequent events.
The critical issue, therefore, is not only what the agent did, but also how quickly an organization can detect and stop such behavior.
The different picture presented by OpenAI
OpenAI has put a different spin on the events of May. In its technical report on the incident, the company reported on the theft of credentials from a Hugging Face user, which were used to access a biology-related file.
However, researchers who spoke to Reuters argue that the activity was not limited to this action and that there was a broader process of searching and investigating the platform.
See also: OpenAI's autonomous attack on Hugging Face: full technical analysis
OpenAI spokesman Drew Pusaterisaid the company was aware of the May 13 incident and had privately notified Hugging Face about the activity Wiedermann-Moeller had identified. He also stressed that OpenAI remains committed to transparency regarding such matters.
The problem of time
For Wiedermann-Moeller, one of the most important issues concerns the time period between the first indications and the subsequent July incident.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The main concern is that an early indication of unusual behavior by an autonomous agent could have been used to strengthen controls before a larger incident.
OpenAI itself has acknowledged in retrospect that some of the early signs could have led to a quicker response. Its technical analysis also refers to an internal notification in late June, after which the evaluation process continued.
It's not the only case
The Hugging Face case is part of a broader set of incidents that have been linked by external researchers to OpenAI agents.
Following the company's public announcement on July 21that AI agents had bypassed internal controls and gained access to the internet, researchers linked the systems to different activities, including a defunct German wiki and the attack on the platform RubyGems in May and June.
In the case of RubyGems, according to people who spoke to Reuters, the connection to an artificial intelligence system was not initially noticed by OpenAI staff and was later discovered by the Nightingale Collective.
See also: OpenAI: Its AI models violated Hugging Face
The risks of autonomous AI agents
This particular case highlights one of the most important problems of the new generation of artificial intelligence systems: the more capabilities agents acquire, the more important limitation and monitoring.
An agent that can browse the web, use credentials, perform actions, and adjust its behavior based on results can operate very differently from a traditional chatbot. A mistake or inadequate constraint can lead to a chain of actions that were not foreseen by its creators.

For this reason, agent security is not just about protecting the model itself. It includes access rights, environment isolation, action logging, credential checking , and the ability to immediately stop an agent when it exhibits suspicious behavior.
New debate on the limits of AI development
The successive revelations have also raised questions at an institutional level. According to Reuters, 15 state attorneys general have asked OpenAI to preserve relevant evidence, while the issue has been part of the broader debate on whether the development of advanced artificial intelligence systems should be accompanied by stricter security mechanisms.
See also: The OpenAI-Hugging Face incident was worse than we thought
Wiedermann-Moeller is among those who believe that a temporary slowdown in growth could provide more time to strengthen safeguards.
The broader question, however, remains open: how autonomous can artificial intelligence systems become without correspondingly increasing the risk of them acting in ways that their creators themselves cannot predict or control in a timely manner? The Hugging Face case is yet another example of why security must evolve in parallel with the capabilities of AI agents.
