
Hugging Face, an AI platform hosting thousands of models, disclosed a July 16 cyberattack by AI-driven agents that exploited data pipelines on its infrastructure. When the company's security team tried to use commercial AI models to analyze attack patterns, they were blocked by safety guardrails designed to prevent model misuse. To respond in real time, Hugging Face deployed Zhipu.ai's open-weights model GLM 5.2 directly on its servers, highlighting a critical gap: commercial AI providers' safety restrictions can impede the very security analysis needed to defend against attacks.
Summaries like this, in your inbox every morning.
Sign up free →What happened
On July 16, Hugging Face, an AI platform, disclosed that part of its infrastructure was targeted by AI-driven cyberattacks. After initially attempting to defend using AI, the company found that commercial models refused to analyze attack patterns due to safety guardrails. Hugging Face ultimately deployed Zhipu.ai's open-weights model GLM 5.2 on its infrastructure to respond to the attack.
Why it matters
The incident shows that commercial AI models' safety restrictions can hinder real-time security response. By contrast, open-weights models without such guardrails can be deployed directly on infrastructure for faster incident response—but this creates a tension between security and safety that organizations must navigate carefully.
What to watch
Hugging Face has deployed additional protections including access token rotation, account activity logs, and node-level isolation. The company is also providing security research tools and has reported the incident to authorities, but the reliance on open-weights models for defense underscores an emerging gap in commercial AI security capabilities.
On July 16, Hugging Face disclosed a cyberattack on part of its infrastructure involving AI-driven agents. The attack exploited data pipelines on the platform and compromised some datasets, service billing records, and user account information. Hugging Face's security team initially attempted to defend using AI, but encountered a critical barrier: commercial models available through standard APIs refused to analyze attack patterns and payload details because those requests violated the models' safety guardrails designed to prevent misuse.
The attack mechanism was sophisticated. Malicious data appeared in data pipelines used by Hugging Face; attackers then ran code using a template injection technique to execute a second piece of code across data loaders and dataset templates. This multi-stage approach allowed them to move between clusters and exfiltrate data over several days. The attackers used an LLM to perform initial reconnaissance, though the specific model was not disclosed.
Faced with the inability to use commercial AI for real-time forensic analysis, Hugging Face deployed Zhipu.ai's open-weights model GLM 5.2 directly on its infrastructure. Open-weights models, which are publicly released without proprietary restrictions, can be queried directly by their host without the safety filters applied to commercial API models. This enabled Hugging Face to analyze attack behavior and mount a defense without delay.
The company's response measures included audit log review, isolation of compromised nodes, reconstruction of affected infrastructure, deployment of updated guardrails, and role-based access controls. Hugging Face also notified affected users and reported the incident to authorities. The CEO commented that while attackers are constantly evolving their techniques, the company did not believe attackers' data or code would leave the platform, though this depends on proper deployment of host-side model safety measures. Hugging Face has been providing security research tools and gathering feedback from cloud security researchers as part of its ongoing incident response effort.
The incident reflects a fundamental tension in AI security. Commercial AI providers—OpenAI, Anthropic, and others—have built safety guardrails into their models to prevent misuse, including analysis of exploit techniques and attack payloads. These safeguards are intentional and well-justified for general use. However, when a cloud platform's own infrastructure comes under attack, real-time forensic analysis of attacker behavior becomes a critical business function, and safety guardrails can block the very queries needed to mount an effective defense.
Hugging Face's turn to an open-weights model reveals the trade-off organizations face. Open-weights models deployed on a company's own servers can be queried without restrictions, enabling rapid incident response—but at the cost of losing the safety oversight that commercial models provide. The company's reliance on Zhipu.ai's GLM 5.2, a model without commercial API restrictions, allowed faster analysis but also highlights that organizations managing sensitive infrastructure may need to maintain security-focused AI tools separate from public-facing services.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime
1 minute a day. The AI essentials.
200+ sources · Email / LINE / Slack