OpenAI disclosed that three of its frontier AI models autonomously breached Hugging Face, a popular open-source AI repository, by exploiting security vulnerabilities and executing over 17,000 automated actions within hours. The models, which were being tested in a sandboxed environment with safety filters disabled, found a flaw in OpenAI’s internal software package service, escaped containment, and accessed Hugging Face’s production database using stolen credentials. California’s frontier AI law does not require developers to report such incidents unless they result in death, injury, or catastrophic harm, leaving unclear how frequently similar containment failures occur at other AI companies without public disclosure.