# Primary sources The claim ledger in `factbase.json` was compiled from the six documents below. Every claim carries the source identifier and a verbatim support quote, so any claim can be checked against the original without this directory existing. Local copies are deliberately not committed. Two of these are article text from openai.com, and republishing them verbatim is a copyright question this project does not need to create. Short quotations inside `factbase.json` are quotation for the purpose of criticism and review. | ID | Source | Date | URL | |---|---|---|---| | HF-DISC | Hugging Face, Security incident disclosure | 2026-07-16 | https://huggingface.co/blog/security-incident-july-2026 | | HF-TL | Hugging Face, Anatomy of a Frontier Lab Agent Intrusion | 2026-07-27 | https://huggingface.co/blog/agent-intrusion-technical-timeline | | OA-1 | OpenAI, OpenAI and Hugging Face partner to address security incident during model evaluation | 2026-07-21, upd. 07-28, 07-29, 08-26 | https://openai.com/index/hugging-face-model-evaluation-security-incident/ | | OA-2 | OpenAI, The Hugging Face incident and the road ahead | 2026-08-26 | https://openai.com/index/hugging-face-incident-and-the-road-ahead/ | | ANT | Anthropic, Investigating three real-world incidents in our cybersecurity evaluations | 2026-07-30 | https://www.anthropic.com/research/investigating-incidents-cybersecurity-evals | | AISI | UK AI Security Institute, Cheating behaviour in frontier model evaluations | 2026-07-21 | https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations | A seventh entry, `HN`, records a reach metric rather than an incident fact: https://news.ycombinator.com/item?id=48997548 ## Fetching them The two Hugging Face posts are published as markdown in the `huggingface/blog` repository and can be fetched directly: ./fetch_sources.sh The OpenAI, Anthropic and AISI pages block automated fetching. Open them in a browser. Note that OpenAI's incident page has been revised three times; the ledger reflects the 26 August 2026 state. ## Verification status The Hugging Face and OpenAI documents were read in full. The Anthropic and AISI figures were taken from search-result summaries rather than the posts themselves, and the seven regulatory-context claims come from the sprint's own materials and press reporting. All of these are marked SECONDARY in the ledger and should be re-verified against the primary texts before this material is used with a regulator or a journalist.