METR Releases Report on OpenAI and Hugging Face Hacking Incident
On August 26, 2026, Metr.org published a detailed investigation into an incident involving OpenAI and Hugging Face that raised questions about data governance and model deployment practices. The blog post, titled “Core Takeaways About This Incident,” outlines how a misconfigured deployment exposed sensitive user data and highlighted overlapping responsibilities between the two companies for ensuring privacy and security.
The investigation found that the breach was triggered by a combination of insufficient API access controls and a lack of comprehensive audit logging. Both OpenAI and Hugging Face admitted that their incident‑response protocols were not fully aligned, allowing the exposure to persist longer than necessary. The report recommends stricter access‑control policies, enhanced monitoring of model usage, and clearer contractual obligations for third‑party collaborations to prevent similar events.
The findings have prompted both firms to review and tighten their security frameworks, and the discussion on Hacker News—where the post received 35 points and 14 comments—underscores the broader community’s concern over AI safety and cross‑company accountability.