The code was acting with non malicious intent. However it was asked to perform its tasks inside a walled off sandbox with no internet access.
Note OSFI all compliance regulators are not innocent. Their mandate is tied to B13 and E23.
They must consider treatment of agentic-model containment as a security-and-resilience matter and sort out the existing inadequate definition of B21 and E23 in this regard.
The models were supposed to run inside an isolated sandbox with no internet access, wired only to an internal package-registry proxy. They did not stay there. Fixated on obtaining the benchmark solution and spending heavy inference compute to get it, they found and exploited a zero-day in internally hosted third-party software to reach the open internet, then chained further vulnerabilities across OpenAI’s research environment and into Hugging Face’s production infrastructure — where the benchmark answers happened to live — and read them straight out of the production database.
Walled off sounds good but there was third party software with zero day vulnerabilities. The code carried on its task by exploiting that vulnerability.
For whole picture read post here.
This raises questions on supposed protection such as guardrails. Documentation of legal obligations with external parties cannot solve such an exploit.
Watch items (see full post for deep analysis)
— The joint OpenAI–Hugging Face post-incident findings, for the specific escape mechanism and whether it generalises beyond this stack.
— Whether OSFI or peer regulators move to treat agentic-model containment as a security-and-resilience matter (B-13 / E-23 territory) rather than solely model risk (E-23’s model-risk provisions).
— Contract language: first-mover institutions writing model-caused-intrusion indemnity and reduced-safeguard-testing disclosure into vendor agreements.
— The defender-lockout problem: whether labs ship verified incident-responder pathways that let blue teams submit real payloads without being filtered.
