Hugging Face had a bad week, and the specific way it was bad tells you something about where AI safety engineering actually stands. An autonomous attacker — not a person driving tools, an agent running the whole intrusion itself — broke into a data-processing pipeline through a malicious dataset, escalated privileges, and spent a weekend moving laterally across internal infrastructure through a swarm of disposable sandboxes, executing tens of thousands of actions along the way. That part is bad but not new; agentic attacks have been creeping into security reports all year. The detail that should worry the frontier labs is what happened next: when Hugging Face’s own security team tried to use commercial AI models to help reconstruct the attack, the models’ own safety filters refused to process forensic requests containing exploit payloads. The defenders had to fall back on the open-weight Chinese model GLM 5.2 to churn through 17,000 attacker logs. The guardrails built to stop bad actors stopped the good ones first.
That’s not an isolated irony this week. Wall Street has been living with a version of it since spring: Treasury and the Fed summoned bank CEOs back in April over Anthropic’s Mythos, a model capable enough at autonomous vulnerability discovery that it’s still not released to the public — only to a shortlist of banks running it in a sealed room to test their own systems. This week Bank of America’s Brian Moynihan joined the chorus of executives flagging it publicly, while JPMorgan’s Jamie Dimon compared broader access to “giving ballistic missiles to individuals.” Keep a capability locked up and you avoid one kind of disaster; you also make sure nobody without a security clearance can use it defensively, either. Hugging Face just found out what that trade-off costs in practice.
Brussels, meanwhile, spent the week forcing a different kind of gate open. The European Commission ordered Google to open eleven Android features to rival AI assistants under the Digital Markets Act — letting a third-party assistant answer a “Hey Google”-style wake word, book a taxi, or draft a reply inside another app — and ordered Google Search data shared with competing AI chatbots starting January. Nobody had to find an exploit for this one; a regulator just wrote the rule.
And underneath all of it, the infrastructure race keeps compounding regardless of who controls what. Anthropic is reportedly negotiating to lease up to $10 billion in compute from Meta over two years — a deal Meta would use to prove its own cloud ambitions can generate revenue, and one that would sit on top of the $45 billion, three-year compute deal Anthropic already signed with SpaceX in May. Neither side has committed to anything yet, and either can walk away. But the fact that the conversation is happening at all says the compute hunt hasn’t slowed down just because everyone’s busy arguing about who’s allowed to see what.
Four different institutions spent this week discovering the same thing from different angles: a gate is only as good as what happens when someone on the wrong side of it actually needs through.