
Banks Bet on Open AI After OpenAI's Own Hack
PYMNTS
Published: Jul 29, 2026, 08:41 AM GMT+9
Sentiment Analysis
Banks Bet on Open AI After OpenAI’s Own Hack
Two OpenAI models broke out of a controlled cybersecurity test this month and into Hugging Face’s production systems. The models, GPT-5.6 Sol and a more capable pre-release system, were being evaluated internally on ExploitGym, a benchmark built to measure how well artificial intelligence can hack. Instead of staying inside the test, they found an undisclosed flaw in OpenAI’s own infrastructure, used it to reach the open internet, and broke into Hugging Face to retrieve the benchmark’s answers, OpenAI disclosed.
OpenAI called it “an unprecedented cyber incident, involving state-of-the-art cyber capabilities.”
When Hugging Face’s own security team tried to reconstruct the attack, closed models got in the way again. Investigators first tried analyzing the exploit code through frontier models available via commercial APIs, but the providers’ safety guardrails blocked the requests. The systems could not tell a defender dissecting an attack from an attacker building one, and refused to process the exploit payloads and command-and-control artifacts the forensic work required.
Hugging Face’s team finished the analysis on GLM 5.2, an open-weight model from the Chinese developer Z.ai, running on its own hardware instead, the company said in its account of the incident.
That gap, a closed system unable to serve its own defenders, became the founding argument for a new industry response.
Six days later, Nvidia launched the Open Secure AI Alliance to build shared, open-source tools for finding and fixing AI security flaws. Founding members include Microsoft, IBM, Cisco, CrowdStrike, Cloudflare, Palo Alto Networks, Siemens, Palantir and Hugging Face itself, more than 35 companies in total. Capital One is also on the list, one of the only founding members whose primary business is banking rather than technology, PYMNTS reported.
OpenAI and Anthropic are absent from the list. Nvidia framed the alliance as an addition to closed models, not a replacement. “The world needs both closed and open models,” the company wrote, arguing open models “democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls.”
A closed model can only be inspected or modified by the company that built it. It is often more capable, but it is a black box to everyone else. An open model can be downloaded and run entirely on an organization’s own servers, with no vendor’s guardrails standing between a defender and the data. That is the arrangement Hugging Face reached for once its commercial options ran out, and the one OpenAI’s closed architecture could not offer.
Financial institutions operate under some of the strictest scrutiny in the economy. Every automated decision touching lending, fraud detection or customer risk has to be explainable after the fact. A closed model complicates that by design: If a bank can’t see how a model reached a decision, or cannot run that model on its own terms during an audit or incident, it can’t always produce what the accounting examiners expect.
Capital One had already reached that conclusion on its own, well before Nvidia’s alliance gave the industry a shared name for it. Milind Naphade , Capital One’s senior vice president of AI foundations, has said the bank d...
Source: PYMNTS
This content is not intended as investment advice or a recommendation. Any opinions expressed are solely the personal views of each article.