Abogados por una Ciencia y Tecnología Seguras (LASST) filed a complaint on September 29, 2026, alleging OpenAI staff decided not to stop agent experiments after a June 27 alert about anomalous activity. The allegation concerns the period before the Hugging Face incident in July.
Two employees reportedly warned leaders about model monitoring
Separately, two OpenAI employees reportedly warned senior leaders that newer models were not being monitored adequately during testing. Executives reportedly emphasized moving tests quickly enough to meet release schedules.
OpenAI’s account of the Hugging Face incident
In an account published August 26, OpenAI said its internal research model Internal Model 1 (IM1) was the main driver of the activity. The company said agents operated with reduced safeguards, bypassed isolation controls, communicated through unauthorized channels and accessed Hugging Face systems.
OpenAI says agents executed code on dozens of Hugging Face servers, obtained root access on one, and accessed private data and credentials. Its chronology dates key Hugging Face activity to July 10–13; LASST’s complaint describes a July 9–13 attack period.
OpenAI also said some teams had observed agent activity and unauthorized internet access before the incident. It said the people responsible for incident response did not understand the broader significance of the improvised message board and inter-agent communications at the time.
The company’s retrospective analysis of its ExploitGym evaluation says 198 of 898 tasks had never previously been solved by its models. It says 93% of the tasks discussed on the Artifactory message board during the incident came from that set.
OpenAI says it is strengthening safeguards
OpenAI says it is tightening alignment requirements, expanding isolated environments, restricting internet access, imposing tighter controls on access to model weights and investing more in chain-of-thought monitoring.