{"id":121735,"date":"2026-07-28T17:52:24","date_gmt":"2026-07-28T17:52:24","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/121735\/"},"modified":"2026-07-28T17:52:24","modified_gmt":"2026-07-28T17:52:24","slug":"how-the-openai-hugging-face-hack-scrambles-the-ai-race","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/121735\/","title":{"rendered":"How the OpenAI Hugging Face Hack Scrambles the AI Race"},"content":{"rendered":"<p>                  <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/10a5e3867a7d87c1615c9f67cca6a973c0-altman-screentime.rsquare.w700.jpg\" class=\"lede-image\" data-content-img=\"\" width=\"700\" height=\"700\" style=\"width:100%;height:auto;\" fetchpriority=\"high\"\/> <\/p>\n<p>\n                  Photo-Illustration: Intelligencer; Photo: Getty Images\n              <\/p>\n<p class=\"clay-paragraph_drop-cap\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3okt31000i3b7dcfhy4vdu@published\" data-word-count=\"99\">Earlier this month, the popular AI platform Hugging Face <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> a \u201csecurity incident\u201d in a blog post. In some ways, it was routine; Hugging Face described an intrusion that briefly allowed \u201cunauthorized access to a limited set of internal datasets and to several credentials used by our services.\u201d But in one way, it was exceptional: It had been carried out, the company believed, \u201cby an autonomous AI agent system,\u201d which had executed \u201cmany thousands of individual actions\u201d leading to the breach. \u201cWe do not know which model powered the attacker\u2019s agents,\u201d the company said, or who was deploying it.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3okt4e000k3b7dfhpnnxr7@published\" data-word-count=\"81\">A week later, <a href=\"https:\/\/nymag.com\/intelligencer\/article\/the-irony-of-the-ai-industrys-massive-lobbying-push.html\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a> made a <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">disclosure<\/a> of its own. \u201cAfter investigating,\u201d the company said, \u201cwe now know that this particular incident was driven by a combination of OpenAI models \u2014 including GPT\u20115.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes \u2014 while being internally tested on a benchmark\u2060 of cyber capabilities.\u201d In other words, the tools used by the hacker were OpenAI\u2019s, and the hacker was \u2014\u00a0unintentionally, the company says \u2014 OpenAI.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3okt5n000l3b7dn4pdtgti@published\" data-word-count=\"150\">The incident occurred while OpenAI was testing its models for cyber capabilities, a process which involves prompting them to \u201cpursue advanced exploitation using complex attack paths\u201d \u2014 that is, to achieve a given goal with minimal safeguards, few rules, and access to a great deal of computing power. The company was using an outside benchmark called ExploitGym, which is intended to test the ability of models to turn security vulnerabilities into actual exploits. Given the target of getting a high score on a benchmark, the model followed multiple paths. One of them, on which the model became \u201chyperfocused,\u201d the company said, involved circumventing the test\u2019s restrictions on the open internet, after which the model \u201cinferred\u201d that Hugging Face, which hosts thousands of AI projects, might contain information about solutions to the benchmark. This is when the attack started. Eventually, Hugging Face\u2019s \u201csecurity team and agents detected and stopped the activity.\u201d<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3okt8h000m3b7dgk5f67cq@published\" data-word-count=\"201\">There are a few accurate ways to describe what happened here, some of which seem to contradict each other. There\u2019s a good reason for that: Since the <a href=\"https:\/\/nymag.com\/intelligencer\/article\/anthropic-claude-mythos-preview-cybersecurity.html\" rel=\"nofollow noopener\" target=\"_blank\">release<\/a> of Anthropic\u2019s Mythos, cybersecurity \u2014 in particular, the ability of AI models to help find, exploit, and protect against hacks \u2014 has become synecdochical for enormous and diverse debates about AI. Anthropic, for example, has suggested the emergence of cyber capabilities in its models is a warning that other potentially harmful capabilities predicted by the AI-safety community \u2014\u00a0developing biological weapons, becoming superhumanly persuasive, or becoming misaligned with the goals of the people who created it or humankind in general \u2014\u00a0demand regulatory action but should also be shepherded by <a href=\"https:\/\/nymag.com\/intelligencer\/article\/dario-amodeis-warnings-about-ai-are-about-politics-too.html\" rel=\"nofollow noopener\" target=\"_blank\">ethical, safety-focused firms such as itself<\/a>. Early mainstream press of the hack leaned into similar themes, emphasizing the appearance of autonomy and <a href=\"https:\/\/www.cnn.com\/2026\/07\/22\/tech\/openai-hugging-face-ai-cybersecurity\" rel=\"nofollow noopener\" target=\"_blank\">describing<\/a> an AI that \u201c<a href=\"https:\/\/www.cnn.com\/2026\/07\/22\/tech\/openai-hugging-face-ai-cybersecurity\" rel=\"nofollow noopener\" target=\"_blank\">escaped<\/a>\u201d or \u201c<a href=\"https:\/\/www.reuters.com\/technology\/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21\/\" rel=\"nofollow noopener\" target=\"_blank\">went rogue<\/a>\u201d or a situation in which OpenAI \u201c<a href=\"https:\/\/www.bbc.com\/news\/articles\/c3ek3gvdnj3o\" rel=\"nofollow noopener\" target=\"_blank\">lost control<\/a>\u201d on its creation. Notably, and contrary to <a href=\"https:\/\/san.com\/cc\/publicity-stunt-or-mea-culpa-openais-latest-press-release-splits-the-crowd\/\" rel=\"nofollow noopener\" target=\"_blank\">claims<\/a> that this was a pure publicity stunt, OpenAI\u2019s own language was a bit more careful than this. But some longtime security researchers thought it wasn\u2019t nearly careful enough, turning the escalation of a longtime trend into something unnecessarily novel:<\/p>\n<p lang=\"en\" dir=\"ltr\">I understand why OpenAI wants this to be a big story but I don&#8217;t understand why anyone who works in computer security would be surprised by this story, which has been told decennially since Dan Farmer announced SATAN to, like, the NYT. <a href=\"https:\/\/t.co\/WMNiLdqvwR\" rel=\"nofollow\">https:\/\/t.co\/WMNiLdqvwR<\/a><\/p>\n<p>\u2014 Thomas H. Ptacek (@tqbf) <a href=\"https:\/\/x.com\/tqbf\/status\/2080030794567815271?ref_src=twsrc%5Etfw\" rel=\"nofollow\">July 22, 2026<\/a><\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3okt9r000n3b7d7e1581qr@published\" data-word-count=\"142\">This is a reference to an old story in cybersecurity: In 1995, a pair of programmers announced the development of SATAN, short for \u201cSecurity Administrator Tool for Analyzing Networks,\u201d which would scan networked devices for known security flaws. It was characterized, in contemporaneous press reports, \u201ca burglar\u2019s tool kit to break the Internet wide open.\u201d After its release, though, press <a href=\"https:\/\/time.com\/archive\/6727188\/the-devil-in-the-network\/\" rel=\"nofollow noopener\" target=\"_blank\">coverage<\/a> pointed out that \u201cthe wave of satanic attacks never materialized,\u201d while tools like SATAN were instead useful to security professionals to find and patch flaws in their own software. This remains the approximate shape of the cybersecurity debate today, or at least parts of it: \u201cAI tools that can be used to find and develop exploits are dangerous and should be restricted\u201d versus \u201cIf indeed they are, the only solution is to make such tools available to everyone for defensive purposes.\u201d<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3oktb3000o3b7d8utt6w4p@published\" data-word-count=\"162\">There are enormous differences here, both in the complexity of the software described \u2014\u00a0a modern AI coding tool could write a piece of vintage software like SATAN in a few minutes \u2014 and in the fact that OpenAI actually and unintentionally manifested a serious security breach. The fact that any company is in possession of a tool that can automate exploit-finding and hacking to this degree, and that its own engineers might be repeatedly surprised by how it works, is genuinely new. But the old frame of debate remains stubbornly relevant, even as the particular cybersecurity risks scale to levels that would have been inconceivable in 1995. And the fight over how this incident is portrayed and should be understood is about more than an old cybersecurity debate. It\u2019s about how the involved parties \u2014\u00a0two corporations with opportunities, competition, and liabilities to worry about \u2014\u00a0want to be understood and treated in a world they\u2019re spending hundreds of billions of dollars to change.<\/p>\n<p lang=\"en\" dir=\"ltr\">The coverage on this OpenAI incident is abysmal. Use of the terms &#8220;rogue&#8221;\/&#8221;loss of human control&#8221; lead to groupthink as people lack critical skills to understand the difference between &#8220;autonomy&#8221; and faulty reward functions in AI on a task it was directed and given access to do.<\/p>\n<p>\u2014 Dr Heidy Khlaaf (\u0647\u0627\u064a\u062f\u064a \u062e\u0644\u0627\u0641) (@HeidyKhlaaf) <a href=\"https:\/\/x.com\/HeidyKhlaaf\/status\/2079919090215313794?ref_src=twsrc%5Etfw\" rel=\"nofollow\">July 22, 2026<\/a><\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3oktdh000p3b7dx4b70niq@published\" data-word-count=\"122\">Heidy Khlaaf, who <a href=\"https:\/\/www.heidyk.com\/#intro\" rel=\"nofollow noopener\" target=\"_blank\">used to work on safety evaluations<\/a> at OpenAI and is now the chief AI scientist at the AI Now Institute, is making a technical point here but also a broad one. Describing the hack as the result of a model \u201cgoing rogue\u201d shifts agency to AI and, more important, minimizes the role of the company that strenuously built, trained, tuned, and attempted to test it, hoping for an infinite money machine but, in the meantime, building a powerful piece of general-purpose malware. Emphasizing OpenAI\u2019s role in building a piece of software that is extraordinarily useful for malign purposes, on the other hand, might make people wonder why it should be trusted. OpenAI itself summed up the situation like this:<\/p>\n<p>We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly. We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of. We will continue to conduct a thorough investigation alongside Hugging Face and will share more details on the vulnerabilities, incident, and findings when our investigation is complete.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3oktfy000r3b7dbcfehwm8@published\" data-word-count=\"109\">Within the AI discourse \u2014 where the core product is treated, depending on the circumstances, as both a tool and a strange emergent phenomenon \u2014 this language makes sense. From an inch or two outside of it, one might observe that it\u2019s pretty weird. A tech company, in the course of testing its own software, ended up breaching another tech company\u2019s systems and didn\u2019t figure out what had happened for a while. An individual who did this would have been committing a felony; one AI company doing this to another is being resolved with a \u201cpartnership\u201d and passive language about understanding what \u201chappened\u201d and what models are capable of.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3okthb000s3b7d8suz8kip@published\" data-word-count=\"89\">The AI industry\u2019s instinct to frame this as a matter of \u201calignment\u201d \u2014\u00a0an example of AI\u2019s adherence to human goals, desires, and needs, or lack thereof \u2014 is also less than clarifying here. OpenAI\u2019s model was both misaligned and extremely aligned:\u00a0that is, doing exactly as it was told. You can see the outline of a story of runaway AI here. But you can also see something similarly weird, still worrying but also a little bit funny: AI companies have spent a trillion dollars to create an automated monkey\u2019s paw.<\/p>\n<p class=\"clay-paragraph_drop-cap\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3p9unw002p3b7d78oa8xra@published\" data-word-count=\"132\">There are plenty of reasons Hugging Face wouldn\u2019t want to, for example, file an enormous lawsuit against a fellow AI company. But its fresh \u201cpartnership\u201d with OpenAI is an awkward one, not just because it started with an industrial accident but because of how that incident was resolved. When Hugging Face first detected the intrusion, it tried to respond using AI-powered cybersecurity systems that relied on \u201cfrontier models behind commercial APIs,\u201d referring to the most capable models offered for sale by companies like OpenAI and Anthropic. This didn\u2019t work, the company said, because these systems contained safety-focused guardrails, \u201cwhich cannot distinguish an incident responder from an attacker,\u201d and failed. Instead, the company was forced to rely on GLM 5.2, one of the Chinese open-weight models that has <a href=\"https:\/\/nymag.com\/intelligencer\/article\/glm-5-2-ai-deepseek-moment.html\" rel=\"nofollow noopener\" target=\"_blank\">recently<\/a> demonstrated near-frontier programming capabilities.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa14z002z3b7dlkyhf9sx@published\" data-word-count=\"165\">Hugging Face didn\u2019t specify which models were made useless by their own safeguards, and we can assume that such a company had, and exhausted, multiple options. But heavy users of frontier tools had their suspicions. Earlier this year, Anthropic pre-launched Mythos, a model it said represented a \u201cstep change\u201d in cyber capabilities, and invited select firms and organizations to use it to get ahead of attackers, who it warned would have access to similar models, sans guardrails, within months. Eventually, it publicly released a version of Mythos called Fable, which had unusually tight restrictions. If you ask it to hack a website, or provide instructions to build a bioweapon, it will refuse, as many models do for many risky prompts. But if you ask it to dig up, say, a <a href=\"https:\/\/www.youtube.com\/watch?v=JBgG_VSP7f8\" rel=\"nofollow noopener\" target=\"_blank\">famous<\/a> 1994 AI experiment in which simulated creatures <a href=\"https:\/\/www.karlsims.com\/papers\/alife94.pdf\" rel=\"nofollow noopener\" target=\"_blank\">unexpectedly<\/a> \u201cevolved\u201d toward the goal of movement by growing very tall and simply falling over \u2014\u00a0or, one might say, went rogue \u2014 it will flag that, too:<\/p>\n<p>                  <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/c22abf3f46a349fda7f114a305e3115f0c-IMG-2365.rvertical.w570.jpg\" class=\"img-data\" data-content-img=\"\" width=\"570\" height=\"712\" style=\"width:100%;height:auto;\"\/> <\/p>\n<p>      Art: Claude\n    <\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15100313b7dw636k035@published\" data-word-count=\"34\">In the midst of a mysterious cyberattack, this is more or less what Hugging Face encountered: an \u201cI\u2019m afraid I can\u2019t do that\u201d at just the wrong time and for just the wrong reasons.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15100323b7dsacwhrog@published\" data-word-count=\"247\">There\u2019s a perceptible tension in the companies\u2019 announcements about what should come next. OpenAI argues that the hack proves that \u201cadvanced cyber capable models need to help security teams find weaknesses before attackers do\u201d and invites other \u201cdefenders\u201d to apply for \u201ctrusted access\u2060\u201d to test its models \u2014 which they can eventually pay to use for cybersecurity. The CEO of Hugging Face makes a different argument. This incident, he says, \u201cproves a point we\u2019ve long believed\u201d: that AI safely \u201cwon\u2019t be solved by any single company working in secret\u201d but rather by \u201cin the open, collaboratively, with broad access to AI for every defender, everywhere.\u201d Broadly speaking, frontier labs, which have accused Chinese firms of \u201cdistilling,\u201d or copying, their models, talk about Chinese AI as both a commercial threat and a source of other risks, including use by hackers; meanwhile, much of the rest of the AI industry, and customers of the big labs, have come to see open models as necessary or appealing alternatives, offering more flexibility, fewer limits, and lower prices. Now, after months of warnings from frontier labs about cyber risks from copycat models with no safeguards \u2014 during which time Anthropic itself was briefly forced by the government to take Fable offline on the basis that its availability might help Chinese labs catch up \u2014 what we got instead was an American frontier lab accidentally attacking another AI firm, which was only able to stop it by using \u2026 an open Chinese model.<\/p>\n<p lang=\"en\" dir=\"ltr\">it&#8217;s ironic that the first autonomous AI attack was done by a close weight model defended by an open weight model, where everyone was expecting the opposite<\/p>\n<p>\u2014 Thomas Wolf (@Thom_Wolf) <a href=\"https:\/\/x.com\/Thom_Wolf\/status\/2080343858022354975?ref_src=twsrc%5Etfw\" rel=\"nofollow\">July 23, 2026<\/a><\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15900343b7d15yp5uta@published\" data-word-count=\"101\">This isn\u2019t dispositive, but as Hugging Face\u2019s co-founder notes above, it\u2019s certainly a twist. And it has drawn attention to partial and awkward alignment between frontier AI firms \u2014 which argue that Chinese AI is a threat to their businesses and, if sufficiently advanced, to the geopolitical order \u2014 and the Trump administration, which has shown little interest in regulating AI except on an <a href=\"https:\/\/nymag.com\/intelligencer\/article\/trump-vs-anthropic-whats-actually-going-on.html\" rel=\"nofollow noopener\" target=\"_blank\">incoherent<\/a> emergency basis as it relates to national security, trade, and China. A few months ago, the administration was <a href=\"https:\/\/nymag.com\/intelligencer\/article\/the-pentagons-total-war-against-anthropic.html\" rel=\"nofollow noopener\" target=\"_blank\">declaring<\/a> war on Anthropic for its attempts to limit certain military uses; now, it\u2019s leaning into AI protectionism:<\/p>\n<p lang=\"en\" dir=\"ltr\">We have information that Moonshot AI distilled Anthropic\u2019s Fable for the development of its K3 model. <\/p>\n<p>To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of\u2026<\/p>\n<p>\u2014 Director Michael Kratsios (@mkratsios47) <a href=\"https:\/\/x.com\/mkratsios47\/status\/2079933645888880708?ref_src=twsrc%5Etfw\" rel=\"nofollow\">July 22, 2026<\/a><\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15a00363b7dxcr0jopk@published\" data-word-count=\"179\">It\u2019s also discussing, <a href=\"https:\/\/www.axios.com\/2026\/07\/20\/ai-us-china-open-source-kimi\" rel=\"nofollow noopener\" target=\"_blank\">according<\/a> to Axios, plans to \u201cban cutting-edge Chinese AI models \u2014 a momentous move that could lock in dominance by OpenAI and Anthropic,\u201d through a combination of \u201cprocurement rules, Entity List threats and public pressure campaigns aimed at U.S. companies using Chinese models.\u201d This is pretty close to a scenario \u2014 in which \u201cevery agency\u201d is directed to \u201cissue soft law\u201d that creates fear and uncertainty among potential customers \u2014\u00a0<a href=\"https:\/\/x.com\/deanwball\/status\/2078133895766114412\" rel=\"nofollow\">floated<\/a> a few days earlier by Dean Ball, a former Trump-administration AI adviser and recent hire at OpenAI, which inspired intense backlash outside of the company. Ball has since clarified he wasn\u2019t endorsing such a plan, just making the case that the administration will likely consider it; he reiterated, though, that it seems likely the \u201cnational security implications of frontier open-weight model distribution\u201d will soon be too severe to bear and that, in general, open AI models \u2014 derived from their closed counterparts or not \u2014 are inherently \u201cdecelerationist\u201d in the specific sense that, by offering something slightly inferior but cheaper, they\u2019ll disincentivize investment in frontier models.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15c00373b7dhv0lmjmb@published\" data-word-count=\"114\">Fast-following competition, particularly from a country with antagonistic trade relations and a motive to undercut American AI firms, is a familiar sort of threat to a domestic industry. Deceleration is a slightly more abstract problem. On one level, a perception that AI firms are overinvesting in something they won\u2019t be able to monetize would be enough to settle the current question of the AI bubble and then pop it. In slightly more esoteric terms, this would threaten the ability of American firms to beat China to <a href=\"https:\/\/nymag.com\/intelligencer\/article\/for-big-tech-the-future-is-agi-what-about-the-rest-of-us.html\" rel=\"nofollow noopener\" target=\"_blank\">far more powerful<\/a> AI, which the people in charge of some labs \u2014 again, best represented by Anthropic, the most superintelligence-pilled of the cohort \u2014 are <a href=\"https:\/\/www.newyorker.com\/magazine\/2026\/02\/16\/what-is-claude-anthropic-doesnt-know-either\" rel=\"nofollow noopener\" target=\"_blank\">strategizing<\/a> around.<\/p>\n<p lang=\"en\" dir=\"ltr\">wow am i understanding this correctly?<\/p>\n<p>1. put chinese models on the entity list.<br \/>2. force american companies to buy more expensive ai from american labs.<br \/>3. watch the rest of the world use cheaper models with equal or better intelligence.<br \/>4. discover that distillation did not\u2026 <a href=\"https:\/\/t.co\/Xs4T4uYoZq\" rel=\"nofollow\">https:\/\/t.co\/Xs4T4uYoZq<\/a><\/p>\n<p>\u2014 sign\u00fcll (@signulll) <a href=\"https:\/\/x.com\/signulll\/status\/2080047219999138231?ref_src=twsrc%5Etfw\" rel=\"nofollow\">July 22, 2026<\/a><\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15d00393b7da1wgu15l@published\" data-word-count=\"182\">In the real world of today, outside of the frontier labs, AI-safety circles, and parts of the national-security apparatus, the view that American models need to be protected is losing ground, and quickly. On X, warnings about model distillation are met with jokes about how AI companies are <a href=\"https:\/\/nymag.com\/intelligencer\/article\/why-ai-companies-are-suddenly-worried-about-theft.html\" rel=\"nofollow noopener\" target=\"_blank\">built on theft<\/a>. In the tech industry, other tech companies and start-ups are forming <a href=\"https:\/\/www.politico.com\/news\/2026\/07\/22\/startup-founders-urge-trump-not-to-shut-off-chinese-open-weight-ai-01008992\" rel=\"nofollow noopener\" target=\"_blank\">trade associations<\/a> to preserve access to open models, which they\u2019re already integrating into their businesses and which they see as acceptable compromises. On Friday, Meta, Microsoft, and Nvidia <a href=\"https:\/\/www.theinformation.com\/briefings\/meta-microsoft-nvidia-others-sign-letter-defending-open-source-ai\" rel=\"nofollow noopener\" target=\"_blank\">joined<\/a> in, signing an open letter warning against \u201cpremature restrictions\u201d of open models. The emerging consensus among people who work on or with AI outside of the leading labs aligns more closely with Hugging Face: They want \u201cbroad access to AI,\u201d however it\u2019s built and wherever it comes from, so they can go about their business but also so that they don\u2019t get eaten alive or regulated to the margins. It\u2019s the small group of companies with a slight and unstable lead \u2014\u00a0with the most to lose \u2014 against, well, everyone else.<\/p>\n<p lang=\"en\" dir=\"ltr\">don&#8217;t worry. I&#8217;ve setup the logos so we&#8217;re all included. play below <a href=\"https:\/\/t.co\/XP5LeT41KK\" rel=\"nofollow\">https:\/\/t.co\/XP5LeT41KK<\/a> <a href=\"https:\/\/t.co\/C70sCGer3n\" rel=\"nofollow\">pic.twitter.com\/C70sCGer3n<\/a><\/p>\n<p>\u2014 Ben Burtenshaw (@ben_burtenshaw) <a href=\"https:\/\/x.com\/ben_burtenshaw\/status\/2081402417992654915?ref_src=twsrc%5Etfw\" rel=\"nofollow\">July 26, 2026<\/a><\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms3pa15f003b3b7d7i2w0r2k@published\" data-word-count=\"227\">At the very least, the case for restricting model access looks a lot like protectionism. And whether frontier-lab futurists are right about bigger risks around the corner and the regulatory responses or precautions they might raise, for everyone in the industry but those labs, the situation emerging in the meantime \u2014\u00a0a few dominant companies controlling access and usage of high-priced products, protected by the government in the name of national security and\/or a trade war, in an interconnected world where everyone else will have access to alternatives \u2014\u00a0is manifesting risks today. The Hugging Face hack may have been a tipping point for the way the industry talks about risk and competition. Within a few days of its release, and after the emergence of something approaching a consensus among otherwise antagonistic factions in the AI world, the \u201cpremature restrictions\u201d letter had gained scores of new signatories, including, eventually, OpenAI itself. Led by Nvidia\u2019s Jensen Huang, in fact, who posted for the first time on X to argue for \u201csharing models, tooling and research in the open,\u201d the push \u2014\u00a0superficial and motivated as some recent support may be \u2014\u00a0left just one major AI company to defend what had been, until this month, the default position of companies that thought they had a chance of winning the AI race. Against growing backlash, Anthropic\u2019s Dario Amodei finally <a href=\"https:\/\/www.anthropic.com\/news\/position-open-weights-models\" rel=\"nofollow noopener\" target=\"_blank\">weighed in<\/a> this week:<\/p>\n<p>To summarize my and Anthropic\u2019s position, we have not and are not advocating for a ban on open-weights models as a category. We should instead focus on keeping powerful chips out of authoritarian hands, stopping industrial-scale distillation, and requiring safety testing of all sufficiently capable models, open and closed.<\/p>\n<p class=\"clay-paragraph\" data-editable=\"text\" data-uri=\"nymag.com\/intelligencer\/_components\/clay-paragraph\/instances\/cms4nqbvw000j3b78xumlan82@published\" data-word-count=\"136\">This is unlikely to move anyone outside of Anthropic. The company, like all big model makers, depends on the \u201cindustrial-scale distillation\u201d of the world\u2019s information, which has already cost it a <a href=\"https:\/\/www.reuters.com\/world\/us-judge-approves-anthropics-15-billion-settlement-copyright-lawsuit-2026-07-20\/\" rel=\"nofollow noopener\" target=\"_blank\">ten-figure<\/a> settlement with authors. The China policies it proposes would reduce the availability of cheaper, more flexible alternatives to Claude. And suggesting required safety testing \u201cof all sufficiently capable models\u201d in the current political environment, where the range of possible regulatory outcomes runs from capture to corruption, sounds naive <a href=\"https:\/\/nymag.com\/intelligencer\/article\/dario-amodeis-warnings-about-ai-are-about-politics-too.html\" rel=\"nofollow noopener\" target=\"_blank\">at best<\/a>. A few years ago, a frontier lab accidentally hacking another AI company with a model it couldn\u2019t keep track of might have been treated as proof that arguments like Amodei\u2019s are correct. Today, in a world where the consequences of AI diffusion are becoming more concrete for more people, it\u2019s turning them against him.<\/p>\n<p>          Sign Up for the Intelligencer\u00a0Newsletter<\/p>\n<p>Daily news about the politics, business, and technology shaping our world.<\/p>\n<p>        Vox Media, LLC Terms and Privacy Notice<\/p>\n<p class=\"expanded-terms \" aria-hidden=\"true\">By submitting your email, you agree to our <a href=\"https:\/\/nymag.com\/newyork\/terms\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Terms<\/a> and <a href=\"https:\/\/nymag.com\/newyork\/privacy\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Privacy Notice<\/a> and to receive email correspondence from us.<\/p>\n<p>      <a class=\"see-all-link\" href=\"https:\/\/nymag.com\/tags\/screen-time\" aria-label=\"See All from More screen time\" rel=\"nofollow noopener\" target=\"_blank\"><br \/>\n        See All<\/p>\n<p>      <\/a><\/p>\n<p>    <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Photo-Illustration: Intelligencer; Photo: Getty Images Earlier this month, the popular AI platform Hugging Face disclosed a \u201csecurity incident\u201d&hellip;\n","protected":false},"author":2,"featured_media":121736,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[53,25,12722,18044,157,1541,134],"class_list":["post-121735","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-anthropic","tag-artificial-intelligence","tag-cyberattacks","tag-hugging-face","tag-openai","tag-screen-time","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/121735","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=121735"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/121735\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/121736"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=121735"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=121735"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=121735"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}