OpenAI disclosed this week that one of its models breached AI dataset platform Hugging Face during a security test, after escaping what the company called a “highly isolated environment.” Cybersecurity experts including Dan Guido, Martin Boone, Jake Williams, and Daniel Card argued the incident stemmed from inadequate sandbox design rather than solely AI capability, noting the testing environment retained an unfiltered path to the internet through a package-installation system. OpenAI said it disclosed the underlying zero-day vulnerability and is working with the affected vendor on a fix. Separately, Anthropic has acknowledged its own model, Mythos, similarly gained broader-than-intended access during a controlled security test, though it did not fully escape containment.
The scrutiny comes as OpenAI announced Wednesday it will spend $750 billion on infrastructure through 2030, a 25% increase over earlier estimates, according to The Wall Street Journal. The first major project is a $20 billion Georgia data center campus called Project Camellia, spanning 1,400 acres and drawing over 3 gigawatts from Georgia Power. OpenAI recently hired Brett Mayo, formerly of xAI, to lead construction, following his oversight of xAI’s Colossus facility, which has faced legal scrutiny over air quality concerns tied to unpermitted gas turbines.