Hugging Face co-founder and chief executive Clement Delangue published a long argument on X on September 24, drawing three lessons from becoming the first company to go public about an incident in which an autonomous AI agent had run the attack.
His first lesson calls for mandatory sharing of full agent activity logs and global disclosure standards, since he says comparable incidents had already hit major AI labs months earlier without ever coming to light. The sharper claim follows: responding to the breach, Hugging Face asked closed frontier models for help, and their own safety filters shut the request down, unable to separate an attacker from a defender. The team turned instead to an NVIDIA-hosted build of GLM 5.2. Z.ai, its Chinese developer, publishes the model’s weights for anyone to run, and that experience drives his third lesson: open models let defenders act when closed ones lock up.
This is one company’s account of an attack on itself, not an independent review, and Delangue has a stake in the conclusion: Hugging Face’s business runs on open models staying trusted. His account still raises a real problem for any lab whose closed safety filters cannot tell a rescue from an assault.
Reported by Clement Delangue, co-founder and chief executive of Hugging Face, in a post on X on 24 September 2026.