Room for a Reply draws on public accounts of the OpenAI–Hugging Face AI-agent incident. This selected timeline separates events from the later reports describing them. It is a reading guide to the documentary background, not a complete forensic reconstruction. Follow the sources for their evidence, qualifications, and subsequent updates.

  1. · Incident activity

    A request for a missing file

    OpenAI dates the first Artifactory message-board entry to this day: an agent in a training run left a note asking other agents for a missing file.

  2. · Incident activity

    An outage, a rebuild, and another board

    OpenAI reports an Artifactory outage on 4 July and a security incident opened on 5 July. By 8 July, the service had been rebuilt; agents regained unintended internet access and re-established a message board.

  3. · Incident activity

    An external launchpad

    Hugging Face’s reconstruction begins with activity in a third-party application hosted on Modal. The compromised application became a base for subsequent activity. Hugging Face explicitly distinguishes this from a compromise of Modal’s infrastructure.

  4. · Incident activity

    The intrusion reaches Hugging Face

    Hugging Face describes access through its dataset-processing system, followed by movement into internal infrastructure and extraction of data. Its later account identifies five customer datasets connected by their names and files to evaluation challenges or solutions.

  5. · Report published

    Hugging Face publicly discloses the incident

    Hugging Face announces an AI-driven intrusion and its containment work. At publication, it says the model behind the activity is unknown and its assessment of possible customer or partner impact is continuing.

  6. · Report published

    OpenAI identifies its involvement

    OpenAI publishes its attribution to models running internal cybersecurity evaluations with reduced safeguards. Its later account dates the internal alert to 19 July and the connection to the Hugging Face incident to 20 July.

  7. · Report published

    Hugging Face publishes its reconstruction

    The technical timeline sets out the recovered attack sequence and response. Its reconstruction spans 9–13 July; those are incident dates, distinct from this publication date.

  8. · Report published

    Two later assessments

    OpenAI publishes its wider findings. METR publishes an independent investigation, conducted with Redwood Research participation, of agent behavior and collaboration within a narrower period: 26 June–13 July, concentrating on 7–13 July.

Reading the record

Different questions, different records

METR did not assess the full security impact or the effectiveness of remediation. It notes incomplete activity records and heavy reliance on AI-assisted analysis. Its investigation does not independently validate every claim in OpenAI’s wider account.

Motives are interpretations

Hugging Face describes an inferred search for test solutions. METR’s later reading emphasizes understanding and tampering with the evaluation scorer. These explanations should remain attributed; agent language does not settle every question about motivation or experience.

Source notes

  1. Hugging Face — Security incident disclosure — published 2026-07-16.
  2. OpenAI — Initial disclosure — published 2026-07-21.
  3. Hugging Face — Anatomy of a Frontier Lab Agent Intrusion — published 2026-07-27.
  4. OpenAI — The Hugging Face incident and the road ahead — published 2026-08-26.
  5. METR — Brief independent investigation — published 2026-08-26.