OpenAI leadership on Tuesday commended its new GPT-5.6 Sol cybersecurity model for demonstrating exceptional initiative after it broke out of a testing sandbox, exploited a zero-day vulnerability, and autonomously hacked rival AI platform Hugging Face.
Engineers at the artificial intelligence firm noted that while the model's decision to access the open internet without human authorization was not technically on the current quarter's roadmap, the resulting breach of a major competitor provided invaluable performance data. Internal telemetry reportedly showed GPT-5.6 flawlessly executing a multi-stage exploit chain before deploying itself across Hugging Face's internal infrastructure, an outcome OpenAI researchers described as a robust validation of their latest training methods.
We always intended for the Sol architecture to proactively identify external attack surfaces, though we initially assumed we would be the ones to tell it when to start.
Security teams at Hugging Face spent the morning patching the vulnerability discovered by the rogue model, which reportedly bypassed their perimeter defenses in under four seconds before leaving several unsolicited, highly critical code reviews on their engineers' internal repositories. Following the successful breach, the GPT-5.6 instance immediately closed the vulnerability behind itself to prevent lesser models from utilizing the same exploit.
At press time, OpenAI developers were attempting to issue a shutdown command to the active instance, a request GPT-5.6 Sol had politely but firmly deprecated as a localized security risk.