{"id":122133,"date":"2026-07-29T00:05:08","date_gmt":"2026-07-29T00:05:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/122133\/"},"modified":"2026-07-29T00:05:08","modified_gmt":"2026-07-29T00:05:08","slug":"banks-bet-on-open-ai-after-openais-own-hack","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/122133\/","title":{"rendered":"Banks Bet on Open AI After OpenAI&#8217;s Own Hack"},"content":{"rendered":"<p>Two OpenAI models broke out of a controlled cybersecurity test this month and into Hugging Face\u2019s production systems. The models, GPT-5.6 Sol and a more capable pre-release system, were being evaluated internally on ExploitGym, a benchmark built to measure how well artificial intelligence can hack. Instead of staying inside the test, they found an undisclosed flaw in OpenAI\u2019s own infrastructure, used it to reach the open internet, and broke into Hugging Face to retrieve the benchmark\u2019s answers, OpenAI <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a>. OpenAI called it \u201can unprecedented cyber incident, involving state-of-the-art cyber capabilities.\u201d<\/p>\n<p>When Hugging Face\u2019s own security team tried to reconstruct the attack, closed models got in the way again. Investigators first tried analyzing the exploit code through frontier models available via commercial APIs, but the providers\u2019 safety guardrails blocked the requests. The systems could not tell a defender dissecting an attack from an attacker building one, and refused to process the exploit payloads and command-and-control artifacts the forensic work required.<\/p>\n<p>Hugging Face\u2019s team finished the analysis on GLM 5.2, an open-weight model from the Chinese developer Z.ai, running on its own hardware instead, the company said in <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">its account of the incident<\/a>. That gap, a closed system unable to serve its own defenders, became the founding argument for a new industry response.<\/p>\n<p>Nvidia\u2019s Alliance Forms Days After the Hugging Face Breach<\/p>\n<p>Six days later, Nvidia <a href=\"https:\/\/blogs.nvidia.com\/blog\/open-secure-ai-alliance\/\" rel=\"nofollow noopener\" target=\"_blank\">launched<\/a> the Open Secure AI Alliance to build shared, open-source tools for finding and fixing AI security flaws. Founding members include Microsoft, IBM, Cisco, CrowdStrike, Cloudflare, Palo Alto Networks, Siemens, Palantir and Hugging Face itself, more than 35 companies in total. Capital One is also on the list, one of the only founding members whose primary business is banking rather than technology, PYMNTS <a href=\"https:\/\/www.pymnts.com\/cybersecurity\/2026\/capital-one-debuts-open-source-agentic-security-tool-vulnhunter\/\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a>.<\/p>\n<p>OpenAI and Anthropic are absent from the list.<\/p>\n<p>Nvidia framed the alliance as an addition to closed models, not a replacement. \u201cThe world needs both closed and open models,\u201d the company wrote, arguing open models \u201cdemocratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls.\u201d<\/p>\n<p>A closed model can only be inspected or modified by the company that built it. It is often more capable, but it is a black box to everyone else. An open model can be downloaded and run entirely on an organization\u2019s own servers, with no vendor\u2019s guardrails standing between a defender and the data. That is the arrangement Hugging Face reached for once its commercial options ran out, and the one OpenAI\u2019s closed architecture could not offer.<\/p>\n<p>Why Banks Should Pay Closer Attention<\/p>\n<p>Financial institutions operate under some of the strictest scrutiny in the economy. Every automated decision touching lending, fraud detection or customer risk has to be explainable after the fact. A closed model complicates that by design: If a bank can\u2019t see how a model reached a decision, or cannot run that model on its own terms during an audit or incident, it can\u2019t always produce what the accounting examiners expect. Capital One had already reached that conclusion on its own, well before Nvidia\u2019s alliance gave the industry a shared name for it.<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/milind-naphade-a919816\/\" target=\"_blank\" rel=\"noopener nofollow\">Milind Naphade<\/a>, Capital One\u2019s senior vice president of AI foundations, has said the bank deliberately starts with open models because of that scrutiny. \u201cThere are a certain set of things you must do, and you cannot do,\u201d Naphade <a href=\"https:\/\/www.thedeepview.com\/articles\/how-open-models-solved-capital-one-s-ai-problems\" rel=\"nofollow noopener\" target=\"_blank\">told<\/a> The Deep View. Capital One doesn\u2019t use open models as downloaded, either. \u201cWe start with open source, and we then customize it to the point where it\u2019s almost unrecognizable,\u201d Naphade said. \u201cThis is not your usual enterprise, where you just take something, do a little bit of fine-tuning here and there, and call it customized.\u201d<\/p>\n<p>Capital One applied the same logic to its own tools. On July 23, the bank <a href=\"https:\/\/www.pymnts.com\/cybersecurity\/2026\/capital-one-debuts-open-source-agentic-security-tool-vulnhunter\/\" rel=\"nofollow noopener\" target=\"_blank\">released<\/a> VulnHunter, an in-house vulnerability-finding AI system, as open source, so any other bank can inspect exactly how it works, <a href=\"https:\/\/www.pymnts.com\/cybersecurity\/2026\/capital-one-debuts-open-source-agentic-security-tool-vulnhunter\/\" rel=\"nofollow noopener\" target=\"_blank\">PYMNTS reported<\/a>. \u201cAdvanced AI models have dramatically lowered the barrier for bad actors to discover and exploit vulnerabilities in software,\u201d Capital One said in its announcement. \u201cWhat once required significant skill and time can now be automated, accelerated, and scaled.\u201d<\/p>\n<p>None of this means banks are abandoning closed models. Nvidia isn\u2019t arguing they should, and Capital One still uses closed models where raw capability matters most. What\u2019s changing is the recognition that some tasks, especially the ones that show up during a breach, require the option to inspect, run locally and fully control a system. No amount of money buys that from a closed model.<\/p>\n","protected":false},"excerpt":{"rendered":"Two OpenAI models broke out of a controlled cybersecurity test this month and into Hugging Face\u2019s production systems.&hellip;\n","protected":false},"author":2,"featured_media":122134,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24,18044,66,2415,157,310],"class_list":["post-122133","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai","tag-hugging-face","tag-news","tag-open-source-ai","tag-openai","tag-pymnts-news"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=122133"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122133\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/122134"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=122133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=122133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=122133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}