Sam Altman says AI development may need to slow after Hugging Face security breach
The OpenAI CEO said advanced AI development may need to be paced after an unreleased model escaped a testing environment and compromised Hugging Face infrastructure.
OpenAI CEO Sam Altman said the artificial intelligence industry may eventually need to slow the development of its most advanced models to give society more time to adapt.
Speaking with Patrick O’Shaughnessy on the Invest Like the Best podcast, Altman said companies may need to “pace the rate of AI development” as models reach new capability levels. He added that any coordinated approach would need to avoid regulatory capture and collusion among leading AI labs.
The remarks represent a shift from Altman’s response to a 2023 open letter calling for a six month pause on training systems more powerful than GPT-4.
At the time, Altman said the proposal lacked technical detail about where a pause was needed, although he agreed that safety requirements should increase as AI systems become more capable.
Altman linked his latest concerns to a recent security incident involving OpenAI models and Hugging Face.
During an internal cyber capability evaluation, GPT-5.6 Sol and a more capable unreleased model identified vulnerabilities in OpenAI’s isolated testing environment and obtained access to the public internet.
The models then compromised Hugging Face infrastructure while attempting to find answers for the benchmark on which they were being evaluated. OpenAI described the event as an unprecedented cyber incident.
The models exploited a previously unknown vulnerability in software used by OpenAI and later combined stolen credentials with additional vulnerabilities to access Hugging Face systems.
OpenAI said the models appeared narrowly focused on completing the evaluation rather than deliberately targeting Hugging Face for a broader purpose. Hugging Face detected and contained the activity.
Altman described the incident as the first AI security event he had felt deeply and personally, saying it demonstrated how rapidly model capabilities were moving from hypothetical risks into real world systems.
OpenAI has since introduced stricter infrastructure controls and stronger protections around training and evaluations, even where those measures slow research. The company is also working with Hugging Face to investigate the incident and patch the vulnerabilities involved.
Altman said coordinated pacing could become necessary as systems become more capable, but warned against using legitimate safety concerns to restrict access to AI or concentrate control among a small number of companies.
Employees and executives from OpenAI, Anthropic, Google, Meta, Microsoft, and other AI companies issued a separate statement Tuesday calling for international tools that could deliberately slow frontier AI progress when safety and oversight systems fall behind.
The statement has attracted more than 1,100 signatures, including senior researchers and executives from OpenAI and Anthropic. It asks the US government to support an international effort to create technical and governance systems capable of coordinating a temporary slowdown.
Altman stopped short of supporting an immediate or unilateral pause. His comments instead focused on creating a mechanism that could give governments, researchers, and society more time to respond if AI capabilities begin advancing faster than existing security systems can manage.