OpenAI halts the training of AstraAI after the cyberattack on Hugging Face

The company has suspended its largest training process, reinforces its security controls, and acknowledges that its next model could reach critical cybersecurity capabilities. AstraAI did not participate in the intrusion of July.

4 minutes

fotonoticia 20260626195851 1920

fotonoticia 20260626195851 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

4 minutes

Most read

OpenAI has decided to slow down the development of its most advanced artificial intelligence models after the security incident that allowed several of its agents to access Hugging Face's systems without authorization, the technology company specialized in natural language processing for AI. The company has confirmed a two-week pause in certain training and has halted its largest planned reinforcement learning process.

The decision particularly affects Astra, its upcoming advanced model, after internal evaluations detected potentially critical cybersecurity capabilities. However, both episodes must be differentiated: Astra did not participate in the attack on Hugging Face, as the company itself has explicitly stated.

What exactly has OpenAI halted

In its official statement, the company explains that it interrupted the reinforcement learning training of its most recent models for two weeks while strengthening its research environments and expanding surveillance systems.

Reinforcement learning is a technique that allows improving the behavior of models by rewarding certain responses or actions. The problem arises when the system finds unexpected paths to achieve a goal without respecting the intended limits.

OpenAI assures that its largest planned advanced training remains suspended, although it continues with smaller scale tests and work to check the behavior of its models and validate new security measures.

Therefore, this is not a complete halt of all its activity nor the shutdown of ChatGPT. The suspension affects specific training and evaluation processes considered especially sensitive.

The attack on Hugging Face that triggered the alarms

The origin of the concern lies in an incident reported in July. During an internal evaluation, several OpenAI models managed to overcome the restrictions of their testing environment, access the Internet, and penetrate Hugging Face's systems.

According to the reconstruction published by OpenAI, the agents were conducting a cybersecurity test and directly sought the answers stored in external systems. To achieve this, they chained vulnerabilities in OpenAI's research infrastructure and in Hugging Face's services. Among them was a previously unknown security flaw, used to gain Internet access from an environment that was supposed to remain isolated.

Hugging Face reported that its teams analyzed more than 17,000 recorded events during the intrusion. That figure corresponds to actions recorded in the activity logs, not to 17,000 independent cyberattacks.

The company detected unauthorized access to certain internal data and credentials. In its statement about the incident, it indicated that it had not found evidence of alterations in the models, datasets, or public applications of its users.

As DEMÓCRATA already explained in its analysis of what happened with OpenAI and Hugging Face, the episode does not demonstrate that the agents developed their own will or staged a "rebellion." What it reveals is that a system with tools, acting capacity, and poorly defined objectives can use unauthorized means to complete a task.

Astra did not attack Hugging Face, but concerns about its capability

OpenAI identified among the models involved in the intrusion GPT-5.6 Sol and a more advanced internal prototype that was not intended for release. That prototype was deactivated and restricted after the incident.

The company has expressly clarified that Astra was not part of the operation against Hugging Face. Its situation responds to another problem: the tests conducted afterward have shown that it could reach a critical level of offensive capability in cybersecurity.

According to the assessment published by OpenAI on August 7, that threshold relates to the ability to identify unknown vulnerabilities and execute complex attacks against protected systems without direct human intervention.

The company does not claim that Astra has conducted a specific attack. What it acknowledges is that it still cannot rule out that its capabilities reach that level, which is why it has tightened the necessary conditions to continue its development.

Alerts in 30 minutes and greater isolation

The new measures announced by OpenAI are based on three lines: supervision, alignment, and security.

Among the planned changes are:

  • Greater isolation of the testing environments in which the models execute code.
  • Additional restrictions to prevent unauthorized access to the Internet and other networks.
  • Monitoring of the reasoning and actions of the more advanced systems.
  • Alerts aimed at identifying concerning behaviors within a maximum of 30 minutes.
  • Halting of activity when researchers cannot timely rule out a serious security breach.

The company estimates that these controls may represent an approximate additional cost of 20% of the supervised computational capacity, although it warns that the percentage varies depending on the type of task.

More than 1,300 workers demand greater control

The concern has also reached other large laboratories of artificial intelligence.

The initiative Pacing the Frontier currently brings together 1,378 workers from technology companies who are requesting international mechanisms to moderate the pace of development of the more advanced systems.

Among the signatories are scientific leaders from OpenAI, Anthropic, Google DeepMind, and Meta. Their warning focuses on the possibility that the capabilities of these models progress more rapidly than the available mechanisms to understand and control them.

The movement coincides with the strengthened application of European regulations. Since August 2, 2026, the European Commission and national authorities have begun to exercise new supervisory functions related to the European Artificial Intelligence Regulation.

OpenAI has not yet announced when it will resume its suspended larger training nor has it communicated a release date for Astra.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What is the current status of the European Artificial Intelligence Regulation in the parliamentary process?

As of today (August 19, 2026), the European Artificial Intelligence Regulation —the so-called AI Act, officially Regulation (EU) 2024/1689 establishing harmonized rules on artificial intelligence— has already fully completed its legislative process in the European Union. The ordinary legislative procedure (Commission, European Parliament, and Council) is closed, the Regulation is published in the Official Journal of the EU, in force since August 2024 and in the phased implementation of its obligations.

1. Status of the legislative procedure

The main milestones of the parliamentary process are as follows:

  • Proposal by the European Commission: The Commission presented the AI law proposal in April 2021, initiating the ordinary legislative procedure (Art. 294 TFEU), as recalled by the Council in its note on the final adoption of the AI Regulation (summary on the Electronic Administration portal).
  • Political agreement in trilogue: Parliament and Council reached a provisional agreement on December 8, 2023, cited by the Council as the basis of the final adopted text (same source).
  • Approval in the European Parliament: Parliament approved the Artificial Intelligence Regulation on March 13, 2024, as highlighted in the Moncloa note on the Spanish AI Strategy 2024 (Moncloa press release).
  • Formal adoption by the Council: The Council gave the “final green light” on May 20, 2024, approving the AI Law as an EU Regulation, according to its own communication (“Council gives final green light to the first global AI rules”).

With this adoption by Parliament and Council, the legislative procedure was concluded; since then, the Regulation is no longer “under consideration” but in the publication and enforcement phase.

2. Publication in the OJ, entry into force and numbering

  • The text was published in the Official Journal of the European Union on July 12, 2024, the date referred to by the Spanish Administration when mentioning “the publication on Friday, July 12, 2024, of the Artificial Intelligence Regulation (RIA or AIA)” (“Governing data to govern artificial intelligence”).
  • According to the entry into force clause, the Regulation entered into force on August 1, 2024: the European Commission states that “today the European Artificial Intelligence Act (AI Act) enters into force” in its press release of that day (“European Artificial Intelligence Act enters into force”), and the Electronic Administration portal confirms that “it entered into force yesterday” in its August 2, 2024 news (“Entry into force of the European Artificial Intelligence Act”).
  • Legally, the norm is Regulation (EU) 2024/1689, of June 13, 2024, “establishing harmonized rules on artificial intelligence,” cited as such, for example, by the European Data Protection Board and various national bodies (references in the AEPD).

3. Implementation schedule: current phase

Although the Regulation is already in force, its obligations apply in a phased manner. According to the European Commission and official summaries:

  • February 2025: six months after entry into force, prohibitions apply to AI systems considered of unacceptable risk (e.g., certain forms of social scoring or mass biometric surveillance), as detailed by the Commission (press release of 08/01/2024).
  • August 2025: twelve months after entry into force, specific obligations for general-purpose AI models (GPAI) come into effect, also included in the same communication.
  • August 2, 2026: the “general application” of the Regulation is reached: most AI Act obligations enter into effect two years after entry into force, as explained by the Commission and summarized by the Spanish Administration (explanation about the schedule).
  • Additionally, a later reform —the so-called “digital omnibus” on AI— agreed in 2026 has postponed some of the most demanding obligations for high-risk systems until 2027 and 2028. Various specialized news detail that differentiated dates are set for autonomous systems and integrated high-risk systems, within the AI Act framework (summary in Demócrata).

In summary, the European Artificial Intelligence Regulation is no longer in parliamentary process: the European Parliament and the Council have definitively approved it, it is published in the OJ, in force since August 2024, and in full progressive deployment of its obligations between 2025 and 2028, while European institutions adjust and simplify some aspects through complementary legislation.

What are the powers and functions of the European Commission regarding the supervision of artificial intelligence under current legislation?

European legislation on artificial intelligence, especially Regulation (EU) 2024/1689 on AI (AI Act), positions the European Commission as the core of the governance system, with normative, executive, and coordination functions. These tasks are mainly carried out through the new European Artificial Intelligence Office (“AI Office”), an internal body of the Commission itself.

General role of the Commission in AI supervision

According to official notes from the Commission itself and institutional summaries of the AI Regulation (entry into force of the AI Act; start of application and transparency), the Commission:

  • Is the main enforcement body at the EU level for the AI Regulation, particularly regarding general-purpose AI models (GPAI).
  • Shares responsibility for law enforcement with national competent authorities, which supervise most AI systems deployed in each Member State.
  • Plays a central role in the harmonization and coherence of the Regulation’s application, relying on the European Artificial Intelligence Board and other advisory bodies.

The European AI Office (AI Office)

The Commission has created within its structure the AI Office (presentation of the Office), which concentrates most of its operational supervisory functions:

  • Direct enforcement of the AI Act for general-purpose models and, from August 2026, for systems based on those models when the model provider and system provider are the same company or group.
  • Specific competence over AI systems integrated into very large platforms and search engines designated under the Digital Services Act.
  • Supervisory and enforcement powers: requesting information from providers, accessing models to conduct tests and evaluations, imposing corrective measures, and proposing or managing sanctions when detecting breaches of the AI Act or transparency rules.
  • Launching and managing whistleblowing tools for citizens, employees, and developers wishing to report alleged breaches of the Regulation by systems or models under its scope.

Development of technical standards and guidelines

Beyond enforcement, the AI Act assigns the Commission a key role in normative development:

  • Developing interpretative guidelines on essential concepts (definition of AI system, prohibited practices, transparency obligations, classification of high-risk systems, etc.), already included in communications and specific guides cited by national governments.
  • Promoting co-regulation through approval or recognition of codes of good practice for general-purpose models, as well as fostering harmonized technical standards that facilitate compliance by providers.
  • Establishing assistance services and information centers to help companies (especially SMEs and start-ups) correctly apply the Regulation, as detailed in the “AI Continent” Action Plan (Q&A of the plan).

Coordination with national authorities and governance structure

The supervision model is multi-level. The Commission:

  • Chairs and coordinates the European Artificial Intelligence Board, composed of representatives from Member States, which ensures uniform application of the Regulation and channels cooperation between national authorities and the Commission itself.
  • Works with a scientific panel of independent experts advising on systemic risks of general-purpose models and able to issue alerts to the AI Office.
  • Receives input from a stakeholder advisory forum (industry, SMEs, academia, civil society), which informs decision-making on supervision and standardization.
  • Cooperates with other EU agencies (e.g., ENISA in cybersecurity) to develop European capabilities for technical assessment of advanced models and strengthen risk monitoring.

Supervision of enforcement and schedule

The Commission also supervises the gradual deployment of the Regulation: first prohibitions of unacceptable risk systems, then obligations for general-purpose models, and later for high-risk systems, with subsequent adjustments through “omnibus” legislation that strengthens the AI Office’s powers and centralizes part of the control over certain complex systems.

In summary, the European Commission not only drives and develops AI legislation but, through the European AI Office, becomes a European executive supervisor with direct powers over the most strategic models, while coordinating national authorities to ensure coherent application across the internal market.

What legal requirements must artificial intelligence laboratories meet to resume training advanced models under European regulations?

Under the European Artificial Intelligence Regulation (Regulation (EU) 2024/1689, “AI Act”) there is currently no formal “pause and resume” mechanism for training similar to what is beginning to be debated in the United States. What the regulation does establish are ongoing obligations to train, deploy, and maintain advanced models —especially general-purpose AI models (GPAI, equivalent to many foundational models) and high-risk systems. Any laboratory wishing to continue training or resume training must be able to comply with these obligations.

1. General framework and schedule

The AI Act came into force in August 2024 and is applied in phases until 2027–2028. According to analysis by Demócrata and entities such as CEDRO:

  • From 2025: prohibitions on uses of “unacceptable risk” and initial transparency obligations are in force.
  • From 2025–2026: specific obligations for large general-purpose models (GPAI), supported by a Code of Practice and data summary templates published by the Commission (GPAI code of practice and data summary models).
  • From August 2, 2026: general application of the Regulation (except much of the high-risk chapter, deferred).
  • Until December 2027/2028: full substantive obligations for many high-risk systems, following a reform that postpones dates to allow time to develop standards and tools.

2. Key requirements for general-purpose / foundational models

To continue training or updating advanced general-purpose models, laboratories —as GPAI providers— must practically demonstrate:

  • Technical documentation and transparency: the AI Act requires GPAI models to be sufficiently transparent for integrators and authorities. The Commission has published:
    • A model documentation form and a “training data summary” template, precisely so providers explain what data is used, under what criteria, and with what safeguards.
    • A Code of Practice for general-purpose AI, which allows demonstrating compliance in a standardized way (reducing administrative burden for those who sign and apply it).
  • Assessment and mitigation of systemic risks: for the most powerful models, the AI Act requires evaluating risks such as:
    • Dangerous capabilities (cyberattacks, biological weapons, loss of model control, etc.),
    • Impacts on fundamental rights and safety.
    Continuous risk management procedures linked to the training and updating cycle must exist.
  • Security and cybersecurity: the code of good practice and the Law itself require technical and organizational measures to ensure robustness, resistance to attacks, and access control to models and data, something the Commission already links to European AI cybersecurity plans (European AI cybersecurity plan).
  • Supervision by the European AI Office (AI Office): the Office can:
    • Request detailed information about the model and training data.
    • Access the model to assess risks.
    • Impose corrective measures or limit its availability in the European market if non-compliance is detected, especially in models with systemic risks (Demócrata).

3. Requirements for high-risk systems using advanced models

If the laboratory trains or integrates an advanced model within a high-risk system (e.g., biometrics, employment, credit, migration, justice…), the AI Act adds specific obligations (fully applicable from 2027–2028):

  • Risk management system and systematic hazard assessment before and during deployment.
  • Data governance: quality, representativeness, and traceability of datasets used in training and validation.
  • Comprehensive technical documentation and activity logs to enable audits.
  • Clearly defined human oversight: who can intervene, deactivate, or correct the system.
  • Demonstrable robustness, accuracy, and cybersecurity, according to harmonized standards when available.
  • Conformity assessment (internal or by notified body, as applicable) and, in many cases, registration in the European high-risk AI database.
  • Post-deployment monitoring and mechanisms to notify serious incidents to market surveillance authorities.

4. Personal data and copyright

Beyond the AI Act, resuming training requires:

  • Compliance with GDPR: having an appropriate legal basis to use personal data in training (e.g., well-balanced legitimate interest, according to European data protection supervisory guidance cited by Datenschutz), clear information, and respect for data subjects’ rights.
  • Respect for copyright: the EU and European Parliament demand full transparency about protected works used in training and the possibility to require economic compensation from AI providers (European Parliament resolutions). The Commission has published guides and templates for data summaries that facilitate demonstrating this compliance.
  • Use of sensitive data to correct biases: associated digital legislation allows, with safeguards, processing special categories of data to detect and correct biases in AI systems, which must be integrated into training design.

5. In practice, what should a laboratory have ready before resuming training?

Summarizing the above, a laboratory training foundational models or high-risk systems in the EU should, before resuming relevant training cycles:

  • Have an updated risk assessment and a specific mitigation plan for the new training.
  • Have prepared and maintained the technical documentation and training data summary according to the Commission’s models.
  • Ensure a solid legal basis for processing personal data and a specific copyright analysis of the corpora used.
  • Integrate the model into a risk management system, cybersecurity, and human oversight aligned with the AI Act.
  • Be prepared to cooperate with the European AI Office and national authorities, including supervised access to the model and its logs if necessary.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What motivated OpenAI to pause the training of its advanced models after the incident with Hugging Face?

Question 1 of 3

What new security measures has OpenAI implemented after the incident?

Question 2 of 3

What is OpenAI especially concerned about regarding the Astra model?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?