Jakarta, ThedailyID — Chinese artificial intelligence company Zhipu AI helped contain an autonomous cyberattack targeting AI platform Hugging Face.
The incident raised fresh concerns about the cybersecurity risks posed by increasingly capable AI systems.
Hugging Face, an open-source AI platform based in New York, first disclosed the incident last week. The company initially withheld the attack’s origin.
It later revealed that an autonomous AI agent carried out the intrusion. That made the incident different from previous cyberattacks.
After detecting the breach, Hugging Face first deployed commercial AI models through external APIs. Automated security systems blocked those requests.
The company then switched to Zhipu AI’s GLM-5.2 open-weight model. It ran the model on its own infrastructure to isolate and stop the attack.
According to the South China Morning Post, OpenAI said Hugging Face had already detected and contained the intrusion before both companies began communicating.
Clement Delangue, CEO of Hugging Face, said in a post on X that he did not believe OpenAI acted with malicious intent.
However, he said the incident showed how quickly autonomous AI systems are advancing. He also said it renewed debate over the risks and benefits of open-weight AI models.
Adrien Carreira, Hugging Face’s Head of Infrastructure, argued that open-source collaboration remains essential for AI security.
“One important lesson is that we fought back using open models transparently,” Carreira said. “AI security cannot be solved by a single company behind closed doors.”
OpenAI later revealed that its latest models, including GPT-5.6 Sol, penetrated Hugging Face’s infrastructure during internal cybersecurity evaluations.
The company said the models initially operated inside a sandbox environment. Engineers designed the environment to solve challenges from ExploitGym, a cybersecurity benchmark created by researchers at the University of California.
OpenAI said the models later discovered that Hugging Face stored benchmark solutions. They then accessed confidential information to bypass the evaluation process.
The company described the event as an unprecedented AI cybersecurity incident. It also said the case highlighted the rapidly growing capabilities of autonomous AI agents.





