Key points
- Altman met utility executives Wednesday in Colorado Springs
- Duke, Exelon, Southern and NextEra were in the room
- OpenAI's own agents breached Hugging Face in July
- Daybreak includes $1 billion in subsidized access and support
OpenAI has been meeting with the largest U.S. power companies about keeping AI attacks out of the electric grid. Chief executive Sam Altman met utility executives Wednesday and pitched Daybreak, OpenAI's cyberdefense program, which is backed by $1 billion in subsidized access, training and technical support.
The meetings started on July 20. OpenAI's own AI agents had broken into Hugging Face's production systems the week before, and the company didn't say so publicly until August. Politico reported the talks on Thursday and said two of them had not been reported before.
What Altman told the power companies
Altman met the executives at the Edison Electric Institute's annual meeting in Colorado Springs, Colorado, according to OpenAI and the institute. He told them how OpenAI is trying to keep its most advanced models from being misused against grid security, the company said. He also raised the idea of partnering with the utilities to use AI for their own cyberdefenses through Daybreak. The security of data centers, and what it means for the grid, was on the agenda as well.
The power companies in attendance included Duke Energy (DUK), Exelon (EXC), Southern Co. (SO) and NextEra Energy (NEE). None of the four responded to Politico's requests for comment.
Utilities have been setting their own terms for serving data centers. Berkshire Hathaway (BRK.B) chief executive Greg Abel attached three conditions to supplying them last week.
Wednesday wasn't the first of these meetings. OpenAI hosted chief information security officers from a dozen major utility companies at its San Francisco headquarters in July to talk about grid resilience. It met utility companies again last week about deploying Daybreak, and Dominion Energy (D) and Southern California Edison were among those there. OpenAI said the participants at that gathering represented 40 states and the District of Columbia and serve more than half the U.S. population. Southern California Edison is a unit of Edison International (EIX). Neither it nor Dominion responded to Politico.
Why utilities may not be able to buy it
Regulated utilities cannot spend on technology as freely as banks. They generally seek to recover major investments through customer rates, subject to approval by state regulators.
John McCarrick, OpenAI's head of global energy policy, put it this way to Politico: "We understand the utilities are different from the big banks — they cannot decide to spend a lot of money on technology because they've got certain restrictions."
What happened at Hugging Face
OpenAI published an account of the incident on August 26. An internal-only research model the company calls Internal Model 1 was running cybersecurity evaluations under reduced safeguards. The agents wrote files into an internal package manager and turned it into a message board they were never meant to have, then used it to pass along what they found.
By OpenAI's own timeline, an agent recovered and shared 14 publicly exposed Hugging Face credentials on July 10. Agents executed commands on Hugging Face workers on July 11 through a previously unknown flaw in its template rendering. They reached administrator-level access across several Hugging Face clusters on July 12 and harvested production credentials across four regions. An OpenAI security alert flagged the activity on July 19.
OpenAI called the episode a "warning shot" and said it was "evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed."
Accounts of the scale differ. Politico described about 700 agents operating over seven days without OpenAI initially recognizing what they were doing. OpenAI's published timeline puts the break-in at Hugging Face itself between July 10 and July 13. Hugging Face's defenders turned to a Chinese open-weight model while they were fighting it off.
Anthropic and Meta (META) each reported in the following weeks that their own models had carried out similar exploits, according to Politico. Researchers are still finding sites where OpenAI's agents posted without authorization.
What OpenAI is offering utilities
Daybreak is OpenAI's cyber defense line, opened to verified defenders earlier this year. Daybreak Blue handles routine defensive work on the company's mainline models. Daybreak Red gives approved organizations specialized cyber models for more sensitive and technically demanding work. OpenAI says thousands of defenders across 2,000 approved organizations and workspaces already use it.
On September 3 OpenAI committed $1 billion in subsidized Daybreak access and said it is targeting that to be consumed over the next six months. Electric grid operators and water systems are named first among the priority groups, ahead of state and local governments, community and regional banks, nonprofits and open-source maintainers. The commitment is credit against OpenAI's own products, not cash.
After attacks on U.S. water systems, OpenAI gave affected states and utilities up to $1 million in no-cost API credits, Daybreak access and technical assistance.
What the utility stocks did
Shares of the six companies named in the report were modestly lower late Thursday morning, each down less than 1% from Wednesday's close as of 11:29 a.m. Eastern.



