This report is from this week’s The Tech Download newsletter. Is it what you see? You can subscribe here.
Last week, when OpenAI’s rogue model launched a cyberattack against startup Hugging Face, the company used another AI model to defend against it and fight back.
It’s a sci-fi-inspired tale of autonomous hacking, and one of the most talked-about technology stories of the week. But the origin of Hugging Face, a model used to combat rogue AI, has also attracted attention.
The startup used GLM 5.2, an open weight system created by Chinese company Z.ai.
Ultimately, it succeeded where its major American rivals had failed.
Hugging Face website on a laptop located in New York, USA on Thursday, August 17, 2023. Nvidia has announced a partnership with Hugging Face, a popular developer of AI models and datasets. This adds a training service to the website that uses Nvidia DGX Cloud, allowing users to utilize the chipmaker’s servers to handle their workloads. Photographer: Gabby Jones/Bloomberg via Getty Images
Bloomberg | Bloomberg | Getty Images
cyber attack
In case you missed it, on Tuesday, OpenAI announced that a combination of its most powerful models and a more capable yet unreleased model escaped its sandboxed test environment, accessed the internet, and exploited a vulnerability to gain access to Hugging Face’s systems.
OpenAI said the model was trying to find information that could be used to falsify ratings, and it was successful.
The source of the attack was initially a mystery to Hugging Face, but days after the incident, the company was working with the AI Institute.
“We have been working closely with the @OpenAI team for the past 24 hours (thank you!) and we strongly believe they had no malicious intent,” Hugging Face CEO Clément Delang wrote in a post on X. “It’s absolutely amazing that all this happened autonomously!”
News broke that OpenAI’s fraudulent model was behind the attack, sending shockwaves through the AI industry. The company called the security incident “unprecedented.”
counterattack
Hugging Face initially looked to frontier models such as Anthropic’s Fable 5 to analyze attacks, Yasin Jarnait, the company’s head of machine learning, told CNBC.
“It didn’t work because the guardrails couldn’t tell if we were trying to defend or attack,” he said, adding that approach was slow and expensive.
Requests to the model were blocked by the provider’s safety guardrails, preventing attackers from identifying incident responders.
“So [Hugging Face] We quickly switched to using Z.ai’s GLM 5.2 as a way to analyze the attack, and using this model we were able to stop the attack very quickly,” said Jernite.
GLM 5.2 was released to much fanfare in June and has been widely adopted by developers.
As an open weight model, businesses can download it, modify it, commercially deploy it, and, crucially in this case, self-host it.
“This had a second benefit: we no longer needed the attacker’s data or credentials. [GLM 5.2] referenced and has left our environment,” Hugging Face said in a blog post about the incident.
All of this comes as the U.S.-China AI arms race intensifies, prompting U.S. lawmakers to consider how to curb the growing adoption of Chinese AI models by their own companies.
Chinese AI companies have been accused of running campaigns to extract information from the systems of their American rivals, prompting calls for measures to restrict access to the models they build.
However, the OpenAI-Hugging Face incident has highlighted the challenges of limiting access to the most capable open source and open weight models, regardless of where they are created.
“While the attackers were bound by a no-use policy, our own forensic work was blocked by the guardrails of the host model we first tried,” Hugging Face said. “The practical lesson for defenders is to vet and prepare a capable model to run on their own infrastructure before an incident occurs.”
For companies that aren’t building AI models in-house, this typically means moving to open source or open weight. Currently, the products with the highest performance are made in China. If the U.S. moves to restrict access to models developed in China, it raises big questions about how to strengthen domestic open source AI to fill the gap.
In a world approaching the era of AI cyberattacks, access to capable and, above all, reliable models is essential.
Latest updates
White House officials accused Chinese AI company Moonshot of gaining access. Nvidia’s advanced chipEven though export regulations prohibit such actions.
European regulators imposed fines google 890 million euros ($1 billion), The company claims that it gives preferential treatment to its own services.
President Trump’s push to manufacture advanced chips in the U.S. is squeezing profits TSMC, The world’s leading chip manufacturer.
OpenAI and Anthropic increase federal lobbying spending to record levels The second quarter of 2026, when the AI industry poured millions of dollars into influencing Washington.
The AI kill switch bill was introduced in Congress on Thursday. This requires AI companies to maintain the ability to shut down, throttle, or pause models.
One more thing
Tesla stock.
I’ve been keeping an eye on tesla Shares of Elon Musk’s electric vehicle and robotics company have fallen sharply over the past 24 hours, as the company tumbled after soaring capital spending and lower-than-expected profits.
