METR, the nonprofit best known for testing frontier AI models before they ship, published its investigation into a hacking incident connected to OpenAI and Hugging Face.
METR posted a "core takeaways" writeup on its blog on August 26, 2026, examining the incident. The post surfaced on Hacker News, where it picked up 24 points and eight comments - a modest showing for a security story tied to two of the most recognizable names in AI. METR normally works as a third-party evaluator, running pre-deployment safety tests for labs including OpenAI, which makes this writeup unusual: an evaluator publishing incident analysis touching one of its own clients.
That positioning is the real story here. METR's evaluations already function as a credibility check that labs point to when they say a model was vetted before release. Having that same organization publish the post-mortem on a security incident, rather than leaving it to OpenAI or Hugging Face to characterize their own breach, changes who readers and regulators are being asked to trust for a straight account.
Worth noting: the writeup came from the evaluator, not from either company with the most at stake in how this incident gets described.