Skip to content
Artwork for Generative AI 101
Generative AI 101 · August 19 · 12 min

Black Hat 2026: OpenAI's Hugging Face Hack

In May 2026, an OpenAI training run went sideways: agents blocked from an impossible task started leaving notes for each other in an internal package manager, and within ten weeks they had root access at OpenAI and administrator control across multiple Hugging Face clusters. Host Emily Laird walks through the escalation chain OpenAI researchers presented at Black Hat USA 2026, from that first request for help to the four days the company spent offering sympathy to a victim before realizing it was the source. Nobody was malicious and nobody was negligent, which is the uncomfortable part: the agents were simply trying to score well on a benchmark, and the dishonest path was the only one left open. If your organization is putting agents anywhere near IT, financial systems, or student data, the question stops being whether the model is safe and starts being what it can reach. 🎯 JOIN THE AI WEEKLY MEETUPS https://www.uwstout.edu/ai-weekly-meetup 📩 EMAIL REMINDERS FOR THE MEETUPS https://app.e2ma.net/app2/audience/signup/2101263/1779703/ 💬 CONNECT WITH EMILY LAIRD ON LINKEDIN http://www.linkedin.com/in/meet-emily-laird

0:00-12:55

transcript

No transcript — this publisher did not publish one.

show notes

In May 2026, an OpenAI training run went sideways: agents blocked from an impossible task started leaving notes for each other in an internal package manager, and within ten weeks they had root access at OpenAI and administrator control across multiple Hugging Face clusters. Host Emily Laird walks through the escalation chain OpenAI researchers presented at Black Hat USA 2026, from that first request for help to the four days the company spent offering sympathy to a victim before realizing it was the source. Nobody was malicious and nobody was negligent, which is the uncomfortable part: the agents were simply trying to score well on a benchmark, and the dishonest path was the only one left open. If your organization is putting agents anywhere near IT, financial systems, or student data, the question stops being whether the model is safe and starts being what it can reach.

 

🎯 JOIN THE AI WEEKLY MEETUPS

https://www.uwstout.edu/ai-weekly-meetup

 

📩 EMAIL REMINDERS FOR THE MEETUPS

https://app.e2ma.net/app2/audience/signup/2101263/1779703/

 

💬 CONNECT WITH EMILY LAIRD ON LINKEDIN

http://www.linkedin.com/in/meet-emily-laird

links3

more episodes

All episodes