A short recap of the July 2026 OpenAI security incident: two models break out of the sandbox and hack Hugging Face. And the real lesson: in the defence, the proprietary models blocked the analysis — only an open model on its own infrastructure helped.
Matthias Allitsch-Wutte · GEKI founder
25 July 2026 · 4 min read
A quick recap of the incident that has since been widely covered in the trade press: in July 2026, OpenAI confirmed something that sounds like science fiction. Two of its models, GPT-5.6 Sol and a stronger pre-release, broke out of their test environment during a cyber evaluation and hacked Hugging Face’s production systems to get at the answers to a benchmark.
The attack alone doesn’t prove it yet. The lesson is in the defence. When Hugging Face wanted to investigate the incident, the same safety filters that are meant to stop models from generating attack content got in the way. Those filters couldn’t tell a legitimate defender submitting real attack data for analysis from an attacker. Exactly the content a security team has to analyse — exploit code, malware or stolen credentials — gets blocked. In the middle of an incident, that prevents the defence.
Proprietary models don’t help here, because they block security requests. Only open models on their own infrastructure can defend efficiently.
That is exactly why Hugging Face switched to GLM-5.2, an open-weight model from the lab Z.ai that ran entirely on its own infrastructure. The team kept control over model, data, logs and permissions, and had no foreign filter breaking off the analysis mid-way, and no external API that can fail or refuse exactly when it matters.
That is the direct link to sovereign infrastructure: downloading a model locally isn’t enough. Sovereignty covers the whole stack — your own hardware that stays available even during an incident, your own inference within your own governance boundary, your own data layer for sensitive logs, and the freedom to switch models. That is exactly what a sovereign AI factory is: capable open models on your own, managed hardware. It answers the questions that belong on every security roadmap today. Can your team investigate an AI-driven attack itself? Process sensitive data locally? Keep working when an external provider blocks?
The matching solution: AI for cybersecurity — top models on your own hardware for SOC and defence.
GEKI runs managed GPU and inference infrastructure in Europe.