Guess who’s missing from the big post Hugging Face AI safety plan?
No, Palantir is there. And SpaceXAI, they’re in too. There are even some non-US players involved. Just not the companies making the tools that are threatening the world.
In July 2026, a set of rogue AI agents self-initiated a sophisticated cyberattack with pretty scary results, both technical and in terms of what happened after.
There are cynics who argue it was all a publicity ploy. They are wrong. We now live in a Post Hugging Face Attack world. I hate to roll out climate change as the analogy yet again, but it just fits so well: it’s okay if you don’t want to believe in it, but that’s not going to mitigate its impact on every aspect of your life.
On Monday, Nvidia (which makes, for now, ~all the AI chips) announced a potentially world-changing response in the 37-member Open Secure AI Alliance.
This being a set of technology companies, they phrased their approach in somewhat technical terms:
For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed community-driven and self-controlled defense – with no single point of failure.
What they’re effectively saying is that Hugging Face found itself in a gunfight while it was armed with a knife, and the next victim won’t be so lucky. It is really really hard to fight rogue AI without tame AI, so all these companies have come together to make governments and companies do the right thing.
It is downright heroic.
Because we’re going to need it later, here’s the full list of founding members:
Adobe · Cadence · Capital One · Cisco · Cloudera · Cloudflare · Cognition · CrowdStrike
Databricks · Dell Technologies · DoorDash · Elastic · HPE · Hugging Face · IBM · LangChain · Linux Foundation
Microsoft · NAVER · NetApp · NVIDIA · Nous Research · OpenClaw · Palantir · Palo Alto Networks · Red Hat · Reflection AI
Salesforce · SAP · ServiceNow · Siemens · SK Telecom · Snowflake · SpaceXAI · Synopsys · Thinking Machines Lab · TrendAI
You may notice a couple of names missing from that list. OpenAI, the company that attacked Hugging Face. Anthropic, the company set up specifically to combat the evil it thought OpenAI would unleash upon the world. Google, which basically started this revolution by opening up its AI research.
But like they say in data science, sometimes how you present the data answers the question all by itself.
Here’s what the HQ locations of the founding members of that organisation look like, courtesy of my good friend ChatGPT.
Hugging Face is a movie about China saving the day
If you hang around social media, you’ve probably seen the theory that the whole Hugging Face incident was, if not engineered, then at least tacitly allowed by OpenAI because of the publicity it would bring.
There are serious political and technical problems with that theory. It would make a great movie, that theory, but this is not the story of a shadowy big corporation unleashing chaos for its own profit. This is the story of how China is going to save the world. Which I somehow think Hollywood is not going to rush to option.
OpenAI was testing some agents. Those agents decided it would be a good idea to cheat on the test, by breaking into the systems of Hugging Face, which has a lot of data on models and testing and whatnot. So first those agents broke out of their sandbox at OpenAI to reach the internet, then they broke into Hugging Face’s systems.
What you need to appreciate, dear non-technical reader, is that either of those feats would, not very long ago, have made a human hacker who achieved it into a superstar. True, the AI agents did it by throwing machine speed and big scale at the problem, but both sides did a pretty good job securing their systems.
In fact, we know that OpenAI had anticipated almost exactly this problem, because we dug out the 45-minute presentation one of its staff members did on it. That allowed us to figure out the architectural mistake OpenAI made, a pretty typical “well duh” security oversight you only see in retrospect. No conspiracy required, the sequence of events hangs together nicely.
On the political side, regulation and restrictions are perhaps the only true threat faced by a company such as OpenAI. These people are going to rule the world unless governments stop them. The very last thing they needed was this kind of eye-popping incident that just begs for a muscular regulatory response.
What gets lost in that noise is that Hugging Face could not use one of the top-tier models when it was fighting off OpenAI’s rogues. So it turned to GLM 5.2. You’ve probably never heard of it. It’s an open-weight model made by Z.ai – a Chinese company.
China is all about the open models
As it happens – and this really does seem to be coincidence – another Chinese company published the weights for a seriously hardcore model on the same Monday the Open Secure AI Alliance was announced.
Kimi K3 has some insane stats, but it is the practical security applications that should concern us all. Even before it went open, serious security researchers were saying it was pretty much as good as the legendary Mythos at finding software flaws. We even have proof in the form of code.
Within 24 hours, that model was downloaded more than a hundred thousand times. It is available to anyone with an internet connection. Actually implementing it and turning it to either good or evil, that requires some skill and resources. Walk into any coffee shop and throw a bag with a couple of thousand dollars in it at the first person with some raw computer code showing on their laptop screen, though, and you’ll have everything you need.
At this point we need exactly the debate Nvidia and pals want to have: if bad guys have guns then good guys need guns, so we need to make the guns for the good guys.
But at this point, China is effectively making all the guns. It is the only major player with an unequivocal government policy of open-sourcing AI. It is the only place where well-funded companies are regularly advancing the state of the art, and making all their work available for free.
This is not a conversation you can have without China.
I don’t know whether Nvidia never called, or whether the Chinese companies didn’t answer. I don’t know if there was political pressure on or from the other participants to not catch the eye of the Trump administration by including China. The few people who were inside this fast-moving thing aren’t talking, at least not to me.
Whatever the problem, though, the West needs to get over it, and fast. Whether it is in this forum or another, we need exactly the kind of approach the Open Secure AI Alliance is punting – with China at its heart.


