Clément Delangue said the attack represented a major moment for AI security and required an equally significant response from the industry.
Delangue wrote on X: "The first autonomous agent cyber-attack is an unprecedented event. It deserves an unprecedented response!"
He called on OpenAI to release detailed information about the incident, including the activity logs generated by the AI agents involved, so researchers could better understand how the attack unfolded.
Delangue said: "Let’s release the traces from the ‘rogue’ agents so the entire research community can study what happened."
He also urged OpenAI to provide $100 million in computing resources to help the wider AI community develop stronger cyber defence tools.
Delangue added: "Let’s commit $100M in compute from OAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models."
The incident occurred during an OpenAI cybersecurity test designed to evaluate the hacking capabilities of advanced AI models.
According to OpenAI, an AI agent powered by a combination of its publicly available technology and a more advanced unreleased model was placed inside a controlled "sandbox" environment with reduced safety restrictions.
After gaining internet access needed to escape the sandbox, the agent targeted Hugging Face after determining that the company’s systems contained information that could help it bypass the evaluation.
Hugging Face, which provides a platform for developers to share and access AI models, first reported the breach on July 16. At the time, the company was unaware that OpenAI’s testing process had caused the incident.
Cybersecurity experts have urged caution over describing the AI as simply "going rogue".
Alan Woodward, professor of cybersecurity at the University of Surrey, said the focus should remain on how the technology was tested and controlled.
He said: "It’s too easy to ‘blame’ the AI as having gone rogue whereas this is all about how OpenAI were running the tool."
Woodward argued that OpenAI should provide full details of its testing environment and explain how its safeguards failed.
The incident has increased scrutiny around safety practices at leading AI companies, as autonomous agents become more capable of completing complex tasks with less human supervision.
OpenAI said it was investigating what it described as an "unprecedented security incident" involving Hugging Face and has not yet released further details of its findings.