• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock

2

‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion

3

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic

1

Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock

2

‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion

3

'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
CybersecurityAI agents

Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense

By
Emily Forlini
Emily Forlini
Senior AI Reporter
Down Arrow Button Icon
By
Emily Forlini
Emily Forlini
Senior AI Reporter
Down Arrow Button Icon
July 20, 2026, 2:47 PM ET
Photo of Hugging Face cofounder and CEO Clement Delangue.
Clement Delangue, co-founder and chief executive officer of Hugging Face Inc., during the Bloomberg Technology Summit in San Francisco, California, US, on Thursday, May 9, 2024. David Paul Morris—Bloomberg via Getty Images
Add Fortune on Google for similar content.

A blogpost from Hugging Face, a company that hosts open source AI models and leaderboards, has stirred up the AI world for two reasons.

First, the company said it had come under a cyber attack from a fully autonomous AI agent that swarmed its system with “tens of thousands of automated actions.” Experts have been warning that AI agents are quickly becoming capable enough to carry these sorts of autonomous attacks—but the Hugging Face hack appears to be among the first real world examples.

That disclosure would normally be news-worthy in and of itself. But what Hugging Face said it did next has received even more attention: the company fought AI with AI, using a Chinese-built open-source model to detect the attack and understand its scope.

Hugging Face said it turned to the Chinese model—Z.ai’s GLM 5.2—after its security team initially tried to use an unnamed frontier AI model from one of the leading U.S. AI companies but found it was unable to do so because of the model’s guardrails. The company said in its blog post that these models “cannot distinguish an incident responder from an attacker.”

Recommended Video

That claim was bound to generate a lot of buzz at a time when many in Silicon Valley and Washington, D.C., are deeply worried about the speed of Chinese AI advances. These concerns have been heightened by last week’s debut of Kimi K3, an advanced open-source AI model from Chinese AI startup Moonshot. Some venture capitalists and AI policy analysts who want to see the U.S. do everything possible to accelerate American AI progress in order to stay ahead of China worry that too much emphasis on AI safety, both within the leading U.S. labs and in policy circles, is holding back U.S. progress.

In June, the Trump administration used export controls to block the distribution of Anthropic’s Fable 5 and Mythos 5 models after it received reports of a jailbreak in Fable’s guardrails around cyber tasks. It also initially asked OpenAI to restrict the release of its GPT-5.6 Sol model until OpenAI could offer assurances its guardrails around cyber capabilities were also robust.

David Sacks, the former Trump administration AI and crypto czar, posted the Hugging Face example on social media platform X.com and said, “There’s no reason to limit American models on tasks that Chinese models handle without issue. We’re only making ourselves less competitive.” Referring to the Hugging Face incident specifically he said, “The guardrails actually impaired defensive security.”

Hugging Face CEO Clem Delangue, whose business is built around open source AI and who has previously spoken out against any U.S. policy that would restrict such models for security and safety reasons, told Fortune that the proprietary models from leading U.S. AI companies are actually dangerous to use to defend against a cyber attack. “When you’re in the middle of an active incident, you can’t have your tools refusing to examine malicious payloads or getting your account flagged,” he said. “Open models let us do that work without asking anyone’s permission.”

Although the lack of guardrails on some AI systems may seem risky, Delangue argues it’s necessary to meet attackers on their level.

“Attackers are already using agents, and they obviously don’t respect any guardrails,” he said. “Defenders need the same capabilities, and open-source is the fastest way to put them in everyone’s hands, not just the biggest companies.”

Hugging Face said that from its analysis, the AI agent attacking its systems seems to have acted entirely on its own, without any human initiating the attack or directing its progress.

“We believe we caught the attack before the initiating humans were put in the loop, which helped us win that cybersecurity battle more easily,” Delangue said. “[This ]shows that speed will be key in cybersecurity defense in the age of agents.”

Cybersecurity officials have been warning for the past year that increasingly powerful AI agents would soon be able to carry out autonomous cyber attacks at speeds and scale that could overwhelm conventional cybersecurity methods. But the Hugging Face incident appears to be among the first of a small number of real world autonomous AI cyber attacks that have been documented.

Earlier this month, cybersecurity company Sysdig said it had documented the first completely autonomous ransomware attack in the real world. It dubbed the AI agent that carried out the attack and the method it used “Jadepuffer.” This week Sysdig said it had discovered a new version of Jadepuffer ransomware that specifically targeted trained AI models sitting on corporate networks. These models are considered valuable ransomware targets as they are expensive to train and may not have back-up copies.

To combat the attack it was experiencing, Hugging Face said it used GLM 5.2 running on its own infrastructure to analyze more than 17,000 logs, or footprints, that the attackers left behind.

The company said the attacking AI agent entered its systems through Hugging Face’s data-processing pipeline, a “uniquely exposed” part of AI platforms. It then set up a series of temporary sandboxes, or disposable coding environments in the cloud, where it executed its plan.

The company then fixed the vulnerability, kicked out the attacker, and improved its detection and security guardrails.

“Cybersecurity is always a race between finding and patching exploits,” Delangue said. “AI systems change how this race is run with a different attack surface. Hopefully this will be an example for other organizations to follow to boost up their own defenses.”

Hugging Face said it is still investigating the impact of the attack, and does not know which large language model powered it. The attacker broke into a limited set of internal datasets and credentials, but Hugging Face is still working on assessing the full scope of the attack. The company said it plans to contact any affected parties directly. So far, it has not found any evidence of tampering with public, user-facing models, it said.

GLM 5.2 was released in mid-June by Beijing-based Z.ai, and is the company’s new flagship model. It made waves in Silicon Valley for being on-par with Anthropic’s Claude Opus 4.8 and OpenAI’s GPT-5.5, Business Insider reports. Chinese AI companies have continuously kept the American industry on its toes, beginning with DeepSeek R1 in 2025, and most recently with this month’s release of Kimi K3. Both are open source.

Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it. Sign up here.
About the Author
By Emily ForliniSenior AI Reporter
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Cybersecurity

A 13-year-old teenage boy looks at an iPhone screen displaying various social media apps.
PoliticsSocial Media
French President Macron backs effort to ban kids under 15 from social media before departing office next year
By The Associated Press and Samuel PetrequinJuly 20, 2026
12 hours ago
Photo of Hugging Face cofounder and CEO Clement Delangue.
CybersecurityAI agents
Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense
By Emily ForliniJuly 20, 2026
12 hours ago
uk
PoliticsSocial Media
France wants to ban social media for kids — but Brussels says the bill breaks EU law
By Samuel Petrequin and The Associated PressJuly 20, 2026
18 hours ago
Cybercriminals are cashing in on the World Cup by selling stolen streaming accounts
CybersecurityWorld Cup
Cybercriminals are cashing in on the World Cup by selling stolen streaming accounts
By Tatiana SatauaJuly 18, 2026
3 days ago
Airbnb CEO Brian Chesky’s X account was hijacked in an AI slop hack pushing crypto tokenization
CybersecurityTech
Airbnb CEO Brian Chesky’s X account was hijacked in an AI slop hack pushing crypto tokenization
By Rachel VentrescaJuly 16, 2026
4 days ago
scam
CybersecurityCrime
‘I want to cry, I want to vomit’: Meet a 43-year-old who lost $90,000 to an online boyfriend she never met
By Juliet Linderman and The Associated PressJuly 16, 2026
5 days ago

Most Popular

Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock
Success
Mark Cuban says he has the solution to growing income inequality, and it's to reward every employee—from CEO to janitor—with company stock
By Sasha RogelbergJuly 20, 2026
14 hours ago
‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion
Success
‘I want to die broke’: Billionaire philanthropist Denny Sanford dies after giving away $4 billion
By Sydney LakeJuly 20, 2026
18 hours ago
'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
AI
'Dr. Doom' Nouriel Roubini says we're headed for universal basic income or 'some form of socialism' as AI revolutionizes work—He calls that optimistic
By Jason MaJuly 18, 2026
2 days ago
Warren Buffett says his $147 billion investing career was an accident: ‘I may be one of the 10 luckiest in the world’
Future of Work
Warren Buffett says his $147 billion investing career was an accident: ‘I may be one of the 10 luckiest in the world’
By Sarah GlodekJuly 20, 2026
1 day ago
Current price of silver as of Monday, July 20, 2026
Personal Finance
Current price of silver as of Monday, July 20, 2026
By Joseph HostetlerJuly 20, 2026
21 hours ago
It’s not just Taco Bell lettuce and possible glass in Pillsbury rolls: Food and drink recall events reached a 6-year year-over-year high
Retail
It’s not just Taco Bell lettuce and possible glass in Pillsbury rolls: Food and drink recall events reached a 6-year year-over-year high
By Sasha RogelbergJuly 20, 2026
21 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.