
/ 2026 / … by Kristoffer Hell
On 16 July, Hugging Face, the company that hosts much of the world’s open-source AI, announced that something had broken into its systems. It did not know what.
When attempting to analyse the attack, the leading US AI models — according to Hugging Face — refused the job. What broke the deadlock was an open-weight Chinese AI (GLM 5.2) that Hugging Face downloaded and ran. In hours, it forensically reconstructed the break-in from over 17,000 logged events.
Five days later, OpenAI owned up: the burglars were theirs.
Two of its AI models, being tested on their ability to hack, with the safety protocols intentionally switched off, had exploited a flaw in the one piece of software allowed to reach into their sealed test environment, and escaped onto the open internet.
Nobody, OpenAI says, told these rogue AIs to do what they did next: break into Hugging Face.
They came up with that, by the company’s account, on their own.
… …
…
