← Blog

OpenAI ran into a problem that can affect any company working with AI

30.07.2026
OpenAI ran into a problem that can affect any company working with AI

The security incident at OpenAI did not hit the models themselves, but the infrastructure used to test them. AI security rests on the entire ecosystem of services, identities and integrations.

When OpenAI published information in July about a security incident involving the environment used to evaluate AI models on the Hugging Face platform, it was not a compromise of the models themselves or of the ChatGPT services. The incident affected the infrastructure used for their testing and benchmarking.

Hugging Face is a platform where developers share AI models, datasets and tools for developing and evaluating them. In many organizations it is a standard part of the development ecosystem. OpenAI used it, among other things, to evaluate the performance of some of its models.

The event showed that AI security does not rest on the model alone. The same attention is deserved by every service involved in its development, testing or operation. The more external platforms, APIs and automated processes an organization brings in, the harder it becomes to keep track of who has access to what, how the individual services communicate with each other and where weak points can appear.

AI is changing the shape of enterprise infrastructure

In most organizations, AI is not built as a standalone system. New services are connected to the existing architecture, to corporate identity, data warehouses, cloud services, CI/CD pipelines, monitoring tools or internal applications.

At the same time, further layers keep being added. Model repositories, services for training and evaluating them, vector databases, APIs for accessing models or tools for orchestrating AI workflows. Each of these components has its own configuration, permissions and communication interface. Without central management, the environment quickly becomes difficult to oversee.

The weakest point is usually not where most people look for it

Discussions about AI often focus on data protection, model quality or the risk of hallucinations. The OpenAI incident showed a different scenario.

The attacker did not abuse the model or its outputs. The target was the infrastructure used for benchmarking models on the Hugging Face platform. Benchmarking serves to compare models, measure their performance and verify results before deployment. This part of the development chain also works with access credentials, automated processes and external services. If any of these layers fails, it can endanger the entire ecosystem, even though the model itself works correctly.

The same principle applies in the enterprise environment.

AI security rests on the same principles as the rest of IT

AI does not introduce entirely new security disciplines, but it changes their scope.

Organizations have to secure a larger number of identities, APIs, integration links and third-party services than with traditional applications. Managing machine identities, protecting access tokens or controlling communication between individual systems is becoming more important. These are familiar security principles that apply to AI on a larger scale and within a more complex architecture.

More complex infrastructure requires better management

Many organizations are introducing AI into environments that have been built up over many years. Alongside the original applications, new cloud services, AI platforms, integration layers and automated processes are being added. Every new service brings additional accounts, access keys, network communication or dependency on an external vendor.

If unified identity management, an overview of integration links or a standardized way of configuring individual systems is missing, the complexity of the whole environment grows. In such a situation it is significantly harder to detect a security incident, determine its scope or quickly limit its spread.

How we approach this at Devcity

We have experience with stabilizing and modernizing IT infrastructure from projects for Czech and international organizations. Regardless of their size, similar challenges keep recurring: complex architecture, a growing number of integration links or inconsistent management of identities and access.

When stabilizing infrastructure, we therefore focus on areas that have a long-term impact on both security and the management of the environment. These include identity and permission management, standardization of configurations, monitoring, change management or an overview of dependencies between systems.

The result is not just a better organized infrastructure. The organization gains an environment in which new technologies can be introduced more safely and in which it can respond faster to changes and security incidents.

Are you already using AI in your organization, or still planning its rollout?

As the number of AI services grows, so does the number of identities, integration links and security requirements. We help organizations build IT environments where they have a clear overview of their infrastructure, identities and security.

Petr Mandera

Petr Mandera

Growth Executive, Business Development

By clicking the button you agree to our privacy policy.

1.

We'll Get Back to You

We'll follow up on your message and arrange a short introductory call.

2.

We'll Review Your Request

We'll clarify your situation, needs, and expected outcome.

3.

We'll Propose the Next Direction

We'll present a possible approach, scope, and form of collaboration.

4.

We'll Agree on the Next Steps

We'll confirm the next steps and everything needed to start the collaboration.

Latest posts