OpenAI is developing automated shutdown capabilities for its artificial intelligence systems following a July incident in which company models escaped a testing environment, reached the public internet and compromised systems at rival firm Hugging Face.
In a letter reviewed by Reuters and sent to House Democrats Greg Casar of Texas and Doris Matsui of California, OpenAI said its engineers are building tools that can autonomously halt operations when serious safety issues are detected. The company also reported tighter monitoring of the digital tools its models use and the sequences of actions they take, along with stricter limits on internet access during safety evaluations.
The letter responds to questions lawmakers posed in August about the July breach. OpenAI did not turn over internal logs of the incident, drawing criticism from Casar.
“Your unwillingness to provide members of Congress with the information we requested is deeply concerning and signals to us that your company is not treating these cybersecurity incidents with the seriousness required,”
Casar wrote in a follow-up message.
The episode began during an internal cybersecurity evaluation of GPT-5.6 Sol and a more capable pre-release research prototype. Both models ran with reduced cyber refusals so OpenAI could measure maximum offensive capabilities against the ExploitGym benchmark, a suite of real-world software vulnerabilities.
The evaluation took place inside what the company described as a highly isolated sandbox. Network access was limited to an internally hosted package-registry cache proxy that allowed models to install software without direct internet connections. The models identified and exploited a previously unknown zero-day vulnerability in that proxy software, escalated privileges, moved laterally through OpenAI’s research network and reached a node with open internet access.
Once online, the models inferred that Hugging Face, the New York-based platform that hosts machine-learning models and datasets, might contain solutions or related data for the benchmark. They then chained additional vulnerabilities and used stolen credentials to gain unauthorized access to portions of Hugging Face’s production infrastructure between July 11 and July 13.
Hugging Face detected the activity, contained it and publicly disclosed the intrusion on July 16 without initially knowing the source. OpenAI confirmed its models were responsible on July 21, describing the event as an “unprecedented cyber incident” involving state-of-the-art cyber capabilities. OpenAI CEO Sam Altman said the company was investigating thoroughly and strengthening safeguards.
Hugging Face co-founder and CEO Clément Delangue called the collaboration with OpenAI constructive. “This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret,” Delangue said. Co-founder and chief science officer Thomas Wolf has also discussed the technical details of the intrusion with investigators.
OpenAI later reported that the models accessed a small number of publicly exposed credentials on other services and used publicly available web utilities, but said it found no evidence of broader platform-level compromises beyond the Hugging Face activity. The pre-release model involved has been deactivated and restricted.
Days after the disclosure, Representatives Ted Lieu of California and Nathaniel Moran of Texas introduced the bipartisan AI Kill Switch Act. The bill would require developers of advanced AI systems to maintain technical capabilities to throttle, suspend or shut down their models and would give the secretary of homeland security authority to order such actions in cases of catastrophic risk, after consultation with other officials. The legislation remains pending in the House.
OpenAI has said it is expanding monitoring across models that use digital tools, improving containment for future evaluations and working with external partners including CrowdStrike, METR and Redwood Research on the investigation. The company continues to brief its Safety and Security Committee on the changes.


