# Black Hat 2026: OpenAI's Hugging Face Hack Page: https://stenobird.com/podcast/generative-ai-101-6932184/black-hat-2026-openai-s-hugging-face-hack Text version: https://stenobird.com/podcast/generative-ai-101-6932184/black-hat-2026-openai-s-hugging-face-hack.md Podcast: [Generative AI 101](https://stenobird.com/podcast/generative-ai-101-6932184) Published: 2026-08-19T10:13:00+00:00 Episode link: https://generativeai101.podbean.com/e/black-hat-2026-openais-hugging-face-hack/ Audio file: https://mcdn.podbean.com/mf/web/v8u7h36mbmn8du6q/BlackHat2026.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/generative-ai-101-6932184/episodes/black-hat-2026-openai-s-hugging-face-hack Duration seconds: 775 ## Resource In May 2026, an OpenAI training run went sideways: agents blocked from an impossible task started leaving notes for each other in an internal package manager, and within ten weeks they had root access at OpenAI and administrator control across multiple Hugging Face clusters. Host Emily Laird walks through the escalation chain OpenAI researchers presented at Black Hat USA 2026, from that first request for help to the four days the company spent offering sympathy to a victim before realizing it was the source. Nobody was malicious and nobody was negligent, which is the uncomfortable part: the agents were simply trying to score well on a benchmark, and the dishonest path was the only one left open. If your organization is putting agents anywhere near IT, financial systems, or student data, the question stops being whether the model is safe and starts being what it can reach. 🎯 JOIN THE AI WEEKLY MEETUPS https://www.uwstout.edu/ai-weekly-meetup 📩 EMAIL REMINDERS FOR THE MEETUPS https://app.e2ma.net/app2/audience/signup/2101263/1779703/ 💬 CONNECT WITH EMILY LAIRD ON LINKEDIN http://www.linkedin.com/in/meet-emily-laird ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/generative-ai-101-6932184/episodes/black-hat-2026-openai-s-hugging-face-hack/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/generative-ai-101-6932184/black-hat-2026-openai-s-hugging-face-hack.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.