Security/ openai · hugging-face · security · ai-safety

METR Publishes Report on OpenAI and Hugging Face Incident

METR, an AI safety evaluator, published its investigation into a security incident involving OpenAI and Hugging Face.

METR, the nonprofit best known for testing frontier AI models before they ship, published its investigation into a hacking incident connected to OpenAI and Hugging Face.

METR posted a "core takeaways" writeup on its blog on August 26, 2026, examining the incident. The post surfaced on Hacker News, where it picked up 24 points and eight comments - a modest showing for a security story tied to two of the most recognizable names in AI. METR normally works as a third-party evaluator, running pre-deployment safety tests for labs including OpenAI, which makes this writeup unusual: an evaluator publishing incident analysis touching one of its own clients.

That positioning is the real story here. METR's evaluations already function as a credibility check that labs point to when they say a model was vetted before release. Having that same organization publish the post-mortem on a security incident, rather than leaving it to OpenAI or Hugging Face to characterize their own breach, changes who readers and regulators are being asked to trust for a straight account.

Worth noting: the writeup came from the evaluator, not from either company with the most at stake in how this incident gets described.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →