Hugging Face CEO details lessons from first public agent cyberattack, advocates for open-source defense
Key point
Hugging Face CEO Clem Delangue outlines three key lessons from the company's July disclosure of an autonomous agent cyberattack, emphasizing transparency, open-source AI for defense, and reframing public discourse.
Details
In a post on September 24, 2026, Hugging Face CEO Clem Delangue reflected on the company's experience as the first to publicly disclose an autonomous agent cyberattack, which occurred in July. He shared three critical lessons from the incident.
The Need for Transparency
Delangue argues that the AI industry requires much more transparency. He notes that similar incidents had occurred months earlier in secret at frontier labs without monitoring. He calls for stronger global standards for incident disclosure, such as mandatory sharing of full agent traces, to help mitigate emerging risks and avoid the dangers of keeping systems behind closed doors.
Countering Asymmetry with Open Source
The second lesson addresses the power asymmetry between attackers and defenders. During the attack, Hugging Face's team was initially blocked by safeguards in frontier closed-source APIs that could not distinguish between defensive actions and malicious ones. They eventually utilized GLM 5.2, an open-source model from Z.ai (accessed via NVIDIA), which offered the necessary flexibility. Delangue asserts that open-source AI is essential for defense because it is less restricted, more privacy-preserving, and orders of magnitude more affordable, helping to distribute capabilities rather than concentrating them.
Reframing the Narrative
Finally, Delangue highlights how AI can stoke fear among the public and policymakers through anthropomorphic framing and sci-fi imagery. He argues that fear-based narratives hinder sound decision-making. Despite being victims, Hugging Face believes AI strengthens cybersecurity by helping fix bugs and defend against attacks, making the world safer when incentives align to equip defenders more than attackers.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.