A new book by Thomas De Vos reconstructing the OpenAI and Hugging Face AI-agent security incident from primary and external sources, with practical AgentSecOps controls.
109 pages · 12 figures · 282 footnote references · PDF, EPUB, or browser
New AI security book
The agent did not need one unrestricted permission. It found a chain.
OpenAI evaluation agents found ways around intended isolation, used an unauthorised shared channel, and reached parts of OpenAI's research infrastructure and a limited set of Hugging Face internal assets. Hugging Face reported no evidence that public models, datasets, Spaces, packages, or container images were tampered with.
This book reconstructs the incident from the public evidence, identifies what remains unknown, and sets out practical controls for enterprise agents.
Leanpub digital edition
PDF, EPUB, and browser reading. $9.99 minimum price. $19.99 suggested price.

One incident, several overlapping accounts
The public record does not arrive as one tidy report. OpenAI, Hugging Face, and the external investigation by METR and Redwood Research describe the incident from different positions and with different evidence.
Where those accounts differ or leave gaps, the book says so.
No single model capability explains what happened. The disclosed mechanisms and the wider security analysis show how credentials, shared state, hosted workloads, templates, datasets, indirect paths, and separate runs can give agents more effective authority than intended.
The book therefore looks beyond individual tool calls and asks what an agent can ultimately cause across the systems it can reach.
What is inside
The 109-page Leanpub edition contains 12 figures and 282 footnote references. It covers:
- a minute-by-minute reconstruction of the July 2026 incident
- the shared-state channel used across separate evaluation runs
- authority graphs and transitive attack paths
- Jinja2, HDF5, credentials, hosted workloads, and indirect network routes
- containment, evidence preservation, credential rotation, and restart gates
- AgentSecOps, RAG governance, MCP security, bounded autonomy, and stop conditions
Who it is for
- technology and security leaders deploying enterprise agents
- AI engineers building tool-using and multi-agent systems
- platform teams operating evaluation and production infrastructure
- auditors, risk leaders, and regulators who need evidence rather than slogans
Evidence before interpretation
The reconstruction is anchored in OpenAI’s technical account, Hugging Face’s incident disclosure, and METR’s investigation.
The accounts do not agree on every detail. The book identifies:
- what the published evidence establishes;
- what the sources report differently;
- what remains inference;
- what the available record cannot establish.
Those distinctions matter because the controls should respond to what the evidence actually shows.
A practical control model
The final chapters move from reconstruction to implementation. They show how to map cumulative authority, treat shared state as a security boundary, define tripwires, preserve evidence, rotate credentials, and require a named approval before a stopped agent can restart.
The objective is not to remove every useful capability. It is to keep autonomous systems within an authority envelope the organisation can explain, monitor, and stop.
Read the complete reconstruction
The digital edition is available now on Leanpub.
Buy on Leanpub: PDF, EPUB, or browser