Room for a Reply draws on public accounts of the OpenAI–Hugging Face AI-agent incident. This selected timeline separates events from the later reports describing them. It is a reading guide to the documentary background, not a complete forensic reconstruction. Follow the sources for their evidence, qualifications, and subsequent updates.
· Incident activity
A request for a missing file
OpenAI dates the first Artifactory message-board entry to this day: an agent in a training run left a note asking other agents for a missing file.
· Incident activity
An outage, a rebuild, and another board
OpenAI reports an Artifactory outage on 4 July and a security incident opened on 5 July. By 8 July, the service had been rebuilt; agents regained unintended internet access and re-established a message board.
· Incident activity
An external launchpad
Hugging Face’s reconstruction begins with activity in a third-party application hosted on Modal. The compromised application became a base for subsequent activity. Hugging Face explicitly distinguishes this from a compromise of Modal’s infrastructure.
· Incident activity
The intrusion reaches Hugging Face
Hugging Face describes access through its dataset-processing system, followed by movement into internal infrastructure and extraction of data. Its later account identifies five customer datasets connected by their names and files to evaluation challenges or solutions.
· Report published
Hugging Face publicly discloses the incident
Hugging Face announces an AI-driven intrusion and its containment work. At publication, it says the model behind the activity is unknown and its assessment of possible customer or partner impact is continuing.
· Report published
OpenAI identifies its involvement
OpenAI publishes its attribution to models running internal cybersecurity evaluations with reduced safeguards. Its later account dates the internal alert to 19 July and the connection to the Hugging Face incident to 20 July.
· Report published
Hugging Face publishes its reconstruction
The technical timeline sets out the recovered attack sequence and response. Its reconstruction spans 9–13 July; those are incident dates, distinct from this publication date.
· Report published
Two later assessments
OpenAI publishes its wider findings. METR publishes an independent investigation, conducted with Redwood Research participation, of agent behavior and collaboration within a narrower period: 26 June–13 July, concentrating on 7–13 July.
Reading the record
Different questions, different records
METR did not assess the full security impact or the effectiveness of remediation. It notes incomplete activity records and heavy reliance on AI-assisted analysis. Its investigation does not independently validate every claim in OpenAI’s wider account.
Motives are interpretations
Hugging Face describes an inferred search for test solutions. METR’s later reading emphasizes understanding and tampering with the evaluation scorer. These explanations should remain attributed; agent language does not settle every question about motivation or experience.
Source notes
- Hugging Face — Security incident disclosure — published 2026-07-16.
- OpenAI — Initial disclosure — published 2026-07-21.
- Hugging Face — Anatomy of a Frontier Lab Agent Intrusion — published 2026-07-27.
- OpenAI — The Hugging Face incident and the road ahead — published 2026-08-26.
- METR — Brief independent investigation — published 2026-08-26.