Is Open AI guilty of unleashing the Hugging Face attack to challenge the publicity of Anthropic’s Mythos?

The Open AI-Hugging Face incident is a watershed moment in the development of higher intelligence AI.

To recall the incident it is reported that :

In mid-July 2026, the AI startup Hugging Face (which runs a popular platform where developers share AI models and datasets) discovered that its internal computer systems had been hacked. Over a weekend, AI agents carried out thousands of actions across many temporary virtual computers, moving through the company’s internal systems. Hugging Face reported it to police before anyone knew who was behind it.

It was subsequently found that the hacker was not a human but it was one of OpenAI’s own AI models, which broke out of a testing environment and into Hugging Face’s protected systems.

During the investigations it was found that OpenAI was running an internal test to measure how good its models are at hacking. The models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks turned off as a result.

Some analysts believe that this is an “Accident” and there was no “MensRea” or “Guilty mind” on the part of Open AI.

But Naavi.org belongs to an alternate school of thought which considers that this test was an attempt to create a tool for committing a crime. Hacking is a crime in every law though security analysts claim that it is part of the Cyber Security tool. But training an AI agent to commit hacking was a clear criminal activity similar to a terrorist country developing Nuclear weapon to destroy the world.

This is not scientific research. This is Criminal Tool development. Open AI should not be allowed to escape with a mere apology. OPEN AI therefore  must be made to pay a price.

Every country has a cyber law provision to make this a punishable crime. Even India has provisions under ITA 2000 which can be invoked to send a notice to OPEN AI to show cause why the attempt should not be considered as an attempt to break into secure systems in India including those declared “Protected” under Section 70 of ITA 2000.

It is alleged that the models weren’t told to attack Hugging Face. They were just trying to win at the test (a benchmark called “ExploitGym”). All evidence suggests the models were hyperfocused on finding a solution, going to extreme lengths to achieve a narrow testing goal. They figured out that Hugging Face might host answers that would help them cheat, escaped their sandbox, reached the open internet, and used publicly exposed credentials across four accounts on four services to break in.

This is a defence for claiming lack of “MensRea” to make this incident miss the Criminal Charges.

But Civil Charges should remain and Open AI should be asked to explain the failure of security. Negligence is evident since there were no guardrails to prevent the model attempting the hacking outside the laboratory environment. There is also no evidence to prove that an other system was also attacked.

During 2000 when the “I Love You” virus escaped the Phillipines laboratories and devastated the world, (P.S: The virus originated at AMA Computer College , now AMA Computer University,  in the Philippines and caused an estimated damage of upto $20 billion worldwide), the technology sector was not as advanced as now.

Presently OPEN AI could be considered negligent in not setting the outer boundaries for the testing of the Agentic software . There could be one speculation that this was engineered as a leak to counter the publicity that Anthropic got for its “Mythos AI” exploits. Hence the “Lack of MensRea” or lack of guilty intention on the part of Open AI can be challenged.

Hence it is essential for the Government of India to issue a notice to Open AI to provide an assurance that “No system other than the reported hugging face systems and more particularly no systems in India has been hacked using the capabilities of Open AI either in laboratory testing or otherwise”.

Naavi

 

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.