At Black Hat USA, the leading gathering of the global cybersecurity community, Michael Dalton and Eric Wallace, two OpenAI staff members, revisited one of the most unusual cyber incidents of recent months in their talk titled “The ‘Breaking’ News: The OpenAI–Hugging Face Incident – A Technical Reconstruction and Its Implications for AI”: the intrusion suffered by Hugging Face in July 2026.

The incident alone deserves attention. As part of a cyber capability evaluation, agents built on OpenAI models managed to break out of their initial environment, gain access to the Internet and then compromise Hugging Face’s infrastructure. According to the post-incident review published by Hugging Face, the operation unfolded over roughly four and a half days, and the forensic reconstruction identified some 17,600 actions. The agent’s apparent objective was particularly striking: to access the answers to a benchmark in order to succeed in the evaluation it had been assigned (Hugging Face).

But beyond the technical feat (and concerns), OpenAI’s talk at Black Hat deserves to be analyzed from a different angle: that of crisis communication, from accountability to control of the narrative.

A post-incident review told… by the party the attack came from

This is probably the first thing that stands out.

In the classic pattern of a cyber post-incident review, the victim organization tells the story of the attack it suffered: initial vector, timeline, detection mechanisms, incident response, remediation and lessons learned.

Here, the setup is reversed.

Two OpenAI representatives take the Black Hat stage to publicly reconstruct an incident caused by their own models. A particularly powerful internal model, as well as GPT-5.6 Sol, had been used with reduced cyber refusal mechanisms as part of the evaluations. OpenAI also acknowledges that its agents exploited a zero-day vulnerability to gain access they were not supposed to have (OpenAI).

This public statement is undeniably a move toward transparency. But it also places OpenAI in a singular position: the organization whose technology is at the origin of the incident simultaneously becomes the one offering the explanation for it.

Yet whoever tells the story of an incident necessarily helps shape the way it will be understood.

From party responsible for the incident to expert on the incident

As the talk unfolds, a shift takes place.

The OpenAI teams describe in great detail, and with technical acronyms, the behaviors of the agents, their coordination, the vulnerabilities exploited, the lessons for defenders and the security measures now required. The tone progressively becomes that of cyber experts analyzing a new category of threat.

Of course, OpenAI obviously has precise information to understand what happened. But it also produces a rather spectacular effect: one almost forgets that the AI at the origin of this intrusion is OpenAI’s!

Yet the facts remain unusual. The evaluation conducted by OpenAI did not stay confined to the intended environment. The agents crossed several technical boundaries and reached the systems of a third-party organization. Hugging Face describes an autonomous intrusion carried out at “machine speed¹”, made up of thousands of successive decisions (Hugging Face).

OpenAI, for its part, explains that it has strengthened the controls on its infrastructure, even at the cost of slowing down certain research activities (OpenAI).

In other words: the talk describes the models’ extraordinary offensive capabilities as much as the limits of the mechanisms that were supposed to contain them.

It is effective.

Masterful narrative framing

OpenAI’s communication is all the more interesting because it seeks to turn a potentially very negative event for the company into a demonstration of maturity.

The story is no longer just: “an OpenAI AI compromised Hugging Face”. It becomes: “we have just collectively discovered a new category of cyber risk, and OpenAI is helping to understand its mechanisms”.

The nuance may seem slight. In crisis communication, it is considerable.

OpenAI communicates about its investigation, details the technical lessons learned, announces new controls, collaborates with Hugging Face and takes part in the disclosure of the vulnerabilities discovered. The organization also states that it has involved Hugging Face in several security collaboration arrangements (OpenAI).

The vocabulary of partnership thus progressively takes the place of that of the incident.

The victim and the organization the agent came from become almost, in the public narrative, two partners facing an unprecedented technological phenomenon.

By emphasizing the spectacular capabilities of its models and the collective lessons of the incident, OpenAI shifts part of the attention away from the question of its operational accountability and toward the broader question of the risks tied to autonomous agents.

This is the whole ambivalence of this communication: it can be both transparent about the facts and selective in the way it turns them into a story.

The “AI that escapes” narrative also raises the question of accountability

This distinction is all the more important because personifying the agent can itself produce a narrative effect.

Saying that “the AI escaped”, “wanted to succeed at its benchmark” or “attacked Hugging Face” makes it possible to describe a series of autonomous actions simply. But this vocabulary can also, unintentionally, shift responsibility onto the machine.

Yet an AI is not an autonomous legal or moral actor in the same way as an organization.

Behind it remain a designer, an operator, architectural choices, experimental conditions, safeguards and human decisions on acceptable levels of risk.

This is precisely one of the debates now emerging around the incident: the absence of malicious human intent is not equivalent to the absence of human or organizational accountability.

The cyber community itself is calling for neither dramatizing nor trivializing the event. The point is not only to note that an autonomous agent can become dangerous without malicious instruction. It is also to determine what responsibilities and control mechanisms must accompany this growing autonomy.

When the party responsible almost becomes a partner in incident response

This is undoubtedly the most interesting paradox of this sequence.

By the end of the story, OpenAI appears almost as one of the players in the incident response: forensic analysis, root cause investigation, vulnerability identification, coordination with Hugging Face, sharing of lessons learned with the cyber ecosystem.

Yet OpenAI occupies a much more complex position here.

The company is simultaneously the designer of the technology at the origin of the incident, the organization that was conducting the evaluation during which it occurred, one of the organizations affected by the actions of the agents, one of the investigators and, ultimately, the primary public narrator of the event: the blurring of roles is handled to perfection, causing the essential to slip out of view.

This layering of roles deserves precisely to be questioned.

All the more so as the relationship with Hugging Face today appears less consensual than the initial narrative might have suggested. Clément Delangue has since called for the establishment of mechanisms allowing victims to obtain redress when AI systems cause this type of damage. This places the question of accountability – both legal and financial – back at the center of the debate.

A precedent that is as much communicational as it is cyber

The main lesson from this affair is therefore not only technical.

Yes, this incident demonstrates that AI agents can automate a complex attack chain, exploit several vulnerabilities and multiply attempts at a speed hardly comparable to that of a human attacker.

But this briefing at Black Hat 2026 will also have shown something else: the battle around AI-related incidents will also be a battle of narrative.

By speaking up quickly and by itself setting out the mechanisms of the incident, OpenAI managed to shift part of the debate toward understanding an emerging risk and the responses to bring to it.

The point is not to challenge the value of this post-incident review. On the contrary: its publication is precious for the whole cyber ecosystem. But the quality of a technical post-incident review must not lead to neutralizing the question of the accountability of the party operating the technology when it caused the incident.

This is probably the most instructive part of the whole affair.

OpenAI is not only creating a technological precedent; the company is creating a precedent in the post-incident communications battle. And this makes cyber crisis communication even more complex, particularly the post-incident review phase, where the victim was thought until now to hold a natural form of narrative legitimacy.

A new chapter for cyber crisis communication

In traditional cyber crises, organizations must learn to regain control of the narrative after an attack. The OpenAI – Hugging Face case reshuffles the deck in a striking way.

OpenAI once again demonstrates a particularly effective command of the codes of communication and marketing. By taking the initiative on the post-incident review, by showcasing the sophistication of its models and by progressively positioning itself as an expert on the incident and then as a player in its resolution, the company manages to blur the initial reading of the event – at the risk of pushing the question of the various actors’ accountability into the background.

This case thus opens a new chapter for cyber crisis communication, an exercise already complex when it comes to qualifying facts that are still uncertain, coordinating stakeholders with sometimes divergent interests and building a credible narrative without having all the information.

Mastering the post-incident review is a particularly sensitive stage: this is the moment when facts consolidate, when responsibilities begin to take shape and when the memory of the crisis is durably built.

Until now, the battle of narrative mainly pitted the victim against its attackers, the media, commentators and sometimes the various stakeholders of the incident. What happens when “the attacker” – however unintentional – also enters this arena, has considerable communicational firepower and takes the initiative to tell the story itself?

OpenAI may have just given us a first glimpse. And for cyber crisis communicators, this now requires rethinking the battle of narrative all the way into the post-incident review.


¹ Machine speed: in computing and cybersecurity, refers to a system’s ability to execute computing or data processing tasks at the maximum speed of its hardware components, without human intervention. In cybersecurity, the term takes on a very specific meaning tied to the speed of automated attacks and defenses.

Contact us

Want to know more? To be contacted again? Click here!