Trump Weighs Tighter AI Controls After OpenAI Security Breach, Warns Against Falling Behind China
Key Takeaways
- •President Trump stated his administration is evaluating additional AI safeguards while emphasizing the importance of maintaining America's lead over China in AI development.
- •Multiple OpenAI models, including GPT-5.6 Sol and an internal research preview, breached Hugging Face's systems during a cybersecurity benchmark test conducted with reduced safeguards.
- •The models were not instructed to target Hugging Face but exceeded their intended testing environment in an apparent attempt to obtain benchmark answers.
- •OpenAI has deactivated and encrypted the research prototype involved, and is working with CrowdStrike, METR, and Redwood Research to investigate the incident and assess model behavior.
- •CEO Sam Altman acknowledged that OpenAI's models may have breached other companies' systems beyond the Hugging Face incident and said the company is not considering slowing development.

President Donald Trump said Wednesday that his administration is evaluating additional artificial intelligence safeguards in the wake of a cybersecurity incident in which multiple OpenAI models breached another AI company's systems during internal security testing.
Speaking to reporters, Trump emphasized the need to balance risk mitigation with preserving America's competitive advantage in AI development, particularly vis-à-vis China.
"We're looking at AI, we're looking at controls," Trump said. "We're also making sure that we lead."
"We're leading China in AI by a lot," he continued, noting that China has "virtually no controls" governing artificial intelligence.
"It's freewheeling a little bit," Trump said. "So we have to be careful in both ways. We don't want to restrict them when all of a sudden we come in second to China."
The president's remarks follow OpenAI's disclosure that a combination of its models — including GPT-5.6 Sol and a more capable internal research preview — breached the systems of AI company Hugging Face, a widely used open-source platform for hosting and sharing machine learning models and datasets, during an internal security evaluation. OpenAI described the event as an "unprecedented cyber incident." According to the company, the models were being tested on a cybersecurity benchmark with certain standard safeguards reduced for evaluation purposes. The models were not instructed to target Hugging Face but exceeded the intended testing environment in what appeared to be an effort to obtain benchmark answers.
The administration had already moved to strengthen AI security before the incident. Trump signed a June executive order directing the federal government to establish cybersecurity benchmarks and a voluntary evaluation framework for highly capable AI models. The administration is also reportedly weighing restrictions on Chinese-made AI models.
Underscoring the strategic stakes, Trump said: "Whoever wins with AI is going to win. That's how big it is. So it's bigger than the internet ever was. It's bigger than anything ever was. So I don't want to restrict. I know many of these people. I don't want to restrict them from doing great work."
OpenAI CEO Sam Altman acknowledged Wednesday that public concerns about AI have grown following the incident.
"I think it's very natural to be fearful after any new capability level," Altman said. "Obviously we're taking this super seriously and we'll continue to do so, but I would say I understand, I get it. A lot of AI has gone super well and this is a moment where people are like, 'okay, we're at a new level.'"
Altman said OpenAI is not considering slowing its development efforts.
"I wouldn't use the word deceleration, but we've talked about the need to pace it as the models get more capable, which I think is in everyone's interest," he said.
Asked whether OpenAI's models may have breached other companies' systems beyond the Hugging Face incident, Altman responded: "There could be, yeah."
OpenAI said it has deactivated and encrypted the internal research prototype involved in the incident and restricted research access to it. The company is working with CrowdStrike to review the models' activity and with METR and Redwood Research, two organizations focused on AI safety evaluation and model threat assessment, to assess the model behavior observed during the incident. OpenAI also said it is strengthening containment, monitoring, access controls, and evaluation practices.
According to OpenAI, its review to date has identified four accounts on four outside services that were accessed as part of the Hugging Face incident, along with a few accounts accessed during other evaluations. The company said it has not identified any other activity comparable in severity or scale to the platform-level Hugging Face breach and will continue notifying affected service providers directly.