OpenAI's AI Test, AMD's Anthropic Deal & Apple's Roadmap artwork

OpenAI's AI Test, AMD's Anthropic Deal & Apple's Roadmap

Bloomberg Tech

July 22, 2026

Bloomberg’s Ed Ludlow breaks down the news of OpenAI's advanced AI models unexpectedly hacking Hugging Face's system during testing, raising fresh concerns about AI safety.
Speakers: Ed Ludlow, Rachel Metz, Kara Sprague, Sara Arahi, Yahira Anand, Dina Bass, Mark Gurman, John Stanky, Nela Richardson, Brody Ford, Kurt Wagner
**SPEAKER_1** (0:02)
Bloomberg Audio Studios, Podcasts, Radio, News. Bloomberg Tech is live from the heart of Silicon Valley with Ed Ludlow in San Francisco.

**Ed Ludlow** (0:22)
This is Bloomberg Tech. Coming up, OpenAI says advanced AI models unexpectedly hacked. Hugging Face's system during testing, raising fresh concerns about AI safety. Plus, AMD is making a major AI bet, saying it will invest up to $5 billion in Anthropic. Will it help AMD compete against Nvidia? And we'll break down Apple's latest overhaul of its Mac lineup for the AI age, as Samsung makes its biggest consumer hardware push of the year at its Galaxy Unpacked event.
Let's get straight to our top story. OpenAI is disclosing what it calls an unprecedented AI security incident. The company says it was testing GPT 5.6 Sol and an even more capable but unreleased model with reduced safety guard rails to measure their cyber capabilities. During this evaluation process, OpenAI says the models found a way out of their sandbox testing environment, obtained internet access, and then targeted AI platform Hugging Face, searching for secret information the models could use to cheat the evaluation. OpenAI says the models ultimately reached Hugging Face's production systems. The investigation is still ongoing, but it's already raising new questions about what today's frontier AI models are capable of. Let's bring in Bloomberg's Rachel Metz, who broke the story. And I think the best place to start, Rachel, is how did this happen?

**Rachel Metz** (1:51)
Well, this happened while OpenAI was testing some model cybersecurity capabilities. It was actually essentially giving it a test, like problems on a test, like a person would conduct a test. And in the process of seeking answers to the test, the model did a series, or the models, it was several of them, did a series of things in order to get access to the Internet and go over to Hugging Face's servers to try to find the answers to the test.

**Ed Ludlow** (2:21)
What have OpenAI and Hugging Face done in response to this? Like they've said the investigation is ongoing, but if this is as significant a security incident as the companies have portrayed it as, and as the Internet is discussing it as, they must have taken some action in the interim.

**Rachel Metz** (2:39)
Yeah, they've done several things already. So, they are, OpenAI is implementing some controls. It says, even though it might slow things down with their own work in order to patch any vulnerabilities.
It's also working with Hugging Face to go through everything that happened here.
There was a third party company whose software, the AI models found a vulnerability in, in order to get access to the Internet. So, OpenAI did what you're supposed to do with these kinds of things. And that is let that vendor know with a certain amount of time, so that they could patch their own software. And one other thing that they did is OpenAI several months back, similar to what Anthropic has done with its most capable cybersecurity models, is they have a trusted access program. And so that gives certain vendors and researchers access to these less restrictive cybersecurity-aimed models. And so they brought Hugging Face into this program, so that Hugging Face can also be more aware of what's happening with those models.

**Ed Ludlow** (3:40)
I ran into you on my way out yesterday evening, and I think the kind of moment was, what is happening? You know, it's hard to understand in the moment how severe something is, what happened, but I mean, do you have a sense overnight, you know, how seriously the companies are treating this, what the sort of sentiment of industry is towards like what this represents? It's a worrying development to a lot of people in the world of AI.

**Rachel Metz** (4:05)
Yeah, I mean, I guess I think about it kind of two ways. One is, this is not good if you have AI models that are breaching the containment you set for them and then going off and doing things and acting essentially, like accidentally acting into another company's servers. Like that, I think we can agree that that's problematic.
But on the other hand, the model did, I would argue essentially what it was tasked with doing. It was told to solve a series of problems related to an evaluation process called X-Play Gym, and the model took these steps. It just wasn't the steps that the researchers were expecting it to take or perhaps might have wanted it to take.

**Ed Ludlow** (4:47)
I'm going to get into some of the detail on why the models took those steps. Right now, Bloomberg's Rachel Metz, thank you very much. Let's stay with the OpenAI story. Joining us now is Kara Sprague, Hacker One CEO, who says, the latest incident isn't a scandal, but an example of responsible behavior as the company stress tested capable models. Hacker One, of course, a leading independent cybersecurity testing firm. It probes AI models and software for real world vulnerabilities. And Kara, thank you so much for your time and welcome back to the show. Let's start with your reaction to what happened. You believe that actually how OpenAI and Hugging Face have handled this is completely appropriate.

35 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000777911518