Get all your news in one place.
100's of premium titles.
One app.
Start reading
Fortune
Fortune
Emily Forlini

OpenAI President says rogue AI attack on Hugging Face 'is indicative of the times we are in' as the company continues to investigate incident

brockman speaks on stage (Credit: Jean Chung—Bloomberg via Getty Images)

OpenAI president and co-founder Greg Brockman suggested that AI models were becoming so capable that companies were struggling to measure all of their capabilities.

Brockman, who was speaking at a roundtable for journalists in New York, said that OpenAI was continuing to investigate an incident it disclosed this week in which “a combination” of its models escaped from a test environment and managed to hack into another company in order to obtain data to cheat on an assessment.

But he said “this incident, to some extent, is indicative of just the moment that we’re in, right?” He said that current AI models were capable across so many different domains that “sometimes it’s hard to lose track of any one dimension that they’re actually very capable at.”

Brockman then said that the particular incident, in which the models attacked the AI platform Hugging Face, highlighted how good OpenAI’s models are at cybersecurity tasks and that he thought it was important these capabilities were available for cyber defenders to use.

“Can we be in a world where defenders are able to spend 10 times as much compute defending and making sure every single piece of software that we have is fully secure relative to anyone else?” he said. That’s the world I think we should strive for.”

Some AI industry watchers have questioned whether the rogue model incident was in some way staged in order to highlight the cyber capabilities of OpenAI’s latest models. There is currently no evidence that this is the case, and news reports suggest that OpenAI’s own safety teams were alarmed by the incident. But it is also true that OpenAI’s blog about the incident concluded with a pitch for its own AI products and a program it has established to give select “trusted partner” companies access to its models for cyber defense.

“We encourage other defenders to apply for trusted access⁠ and experiment with these models now to translate these capabilities into better prevention, faster detection, and more effective incident response,” OpenAI wrote in the blog.

Brockman said OpenAI was taking the incident “very seriously” and that it was “looking into every single piece of our pipeline to think about the right ways to respond.”

When asked about proposals that the U.S. ban American companies from using Chinese-made AI models, something which the Trump administration is reportedly mulling, the OpenAI executive said “AI is something that is very important to democratize” and that “having more models is a good thing.” He stopped short, however, of explicitly saying he disagreed with the idea of a ban.

Brockman is among the largest donors to Trump’s political war chest, having given $25 million in Janaury to the Trump-aligned super PAC MAGA, Inc. The move was widely interpreted as an attempt to curry Trump’s favor.

Brockman said he had not been in any conversations with the administration about banning Chinese AI models in the U.S.

He suggested that a ban might distract from more pressing policy concerns, particularly around AI safety. “For any model, it’s not really about who creates it,” he said. The more important questions, he said, include: “How do you evaluate a model? How do you think about its safety? How do you think about its use cases? How do you understand its alignment?”

The Trump administration is weighing a ban on cutting-edge Chinese AI models after Beijing-based Moonshot AI released its powerful Kimi K3 model, Axios reported this week. That model came close to equally the performance of the best models from American AI companies Anthropic and OpenAI, but was potentially much cheaper to use.

The White House has accused Moonshot of stealing the intellectual property of U.S. AI labs to build Kimi K3 through a process known as “distillation,” in which the outputs of one AI model are used as training inputs for another model. The terms and conditions of most AI vendors prohibit distillation but legal experts say the tactic is a legal gray area rather than a clear case of IP theft. In particular, Michael Kratsios, the director of the White House Office of Science and Technology Policy, said Moonshot had used outputs from Anthropic’s Fable 5 to train Kimi K3.

The strengths of Chinese AI models were also highlighted by the OpenAI rogue AI incident. In that case, Hugging Face, the company that came under attack, said it was forced to use a Chinese open source model, Z.ai’s GLM-5.2, to defend itself from the attack. Hugging Face said it had to do this because it first tried an unnamed American AI model but found its strict guardrails around cyber capabilities rendered it useless for conducting a defense of the on-going attack.

When asked about whether he thought it was concerning Hugging Face had to use a Chinese-built model, Brockman did not directly answer the question. He reiterated the importance of having access to as many AI tools as possible. “We really think that putting these tools in defenders’ hands is very important, and that’s something that we’ve actually really pushed towards,” he said.

Nvidia CEO Jensen Huang seems to agree with Brockman. This week he called the latest Chinese AI models “excellent” and saying they “should be used.”

The U.S. government’s concern about widespread access to increasingly powerful, and potentially dangerous, AI has complicated the business of frontier labs like Anthropic and OpenAI. The Trump administration effectively forced Anthropic’s Fable model off the market for most of the month of June over security concerns. Brockman said OpenAI had to work “very closely” with the administration on the rollout of its GPT-5.6 model before its release shortly on July 9.

When asked whether open source models are a threat to OpenAI’s business since they can offer similar performance at a lower cost, Brockman disputed the commonly-held belief that open source models were necessarily less expensive because, while the models are often free to download, companies wanting to use them generally have to purchase their own cloud computing capacity to do so.

“One narrative I would love to correct on cost [is that] it’s not the case that open source models are magically cheap,” he said. “Everything’s running on the same hardware.” He said OpenAI works to make its models as cheap as possible for the task at hand. Surprisingly, he seemed relieved businesses are beginning to scrutinize the cost of AI and demand more clear ROI.

“Now that people actually care about price, which was not the case three months ago, we are delighted because we have always been the most efficient, most price performance models,” he said. “Now people actually care about that, and so we’re like, ‘Yes, the world is rational again.'”

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.