Making artificial intelligence practical, productive & accessible to everyone. Practical AI is a show in which technology professionals, business people, students, enthusiasts, and expert guests engage in lively discussions about Artificial Intelligence and related topics (Machine Learning, Deep Learning, Neural Networks, GANs, MLOps, AIOps, LLMs & more).
The focus is on productive implementations and real-world scenarios that are accessible to everyone. If you want to keep up with the latest advances in AI, while keeping one foot in the real world, then this is the show for you!
Welcome to the Practical AI Podcast, where we break down the real world applications of artificial intelligence and how it's shaping the way we live, work, and create. Our goal is to help make AI technology practical, productive, and accessible to everyone. Whether you're a developer, business leader, or just curious about the tech behind the buzz, you're in the right place. Be sure to connect with us on LinkedIn, X, or Blue Sky to stay up to date with episode drops, behind the scenes content, and AI insights. You can learn more at practicalai.fm.
Narrator:Now onto the show.
Daniel:Welcome to another fully connected episode of the Practical AI Podcast. This is where Chris and I don't have a guest, but we get to dive into one of the topics that's been floating around in the AI news, maybe spend some time learning ourselves and also hopefully helping you learn learn and level up your machine learning and AI game. I'm Daniel Whitenack. I'm CEO at Prediction Guard, and I'm joined as always by my cohost, Benson, who is a principal AI and autonomy research engineer. How are you doing, Chris?
Chris:Doing good. You know, there's always so much good stuff to talk about there, but boy, do we got a good one today.
Daniel:Yeah. This is a multifaceted topic that, yeah, just has so much packed into it. Originally, when I saw this and what we're talking about here, we're in for those that are maybe listening later, we're in July, the kind of July 2026. And what has just happened in in now time is an exploit or a hack of Hugging Face, which for those that aren't familiar, Hugging Face is kind of the online repository hub for models, datasets, benchmarks, a a lot of different things for the AI community. And kind of like what GitHub is for code, hugging faces for models and datasets and other things.
Daniel:And they reported originally, you sent me the link, Chris, and this is when we didn't kind of know much, just that Hugging Face had been compromised in some way. And, boy, it has developed in interesting ways as we've learned more. I'm kind of amazed. I think both of us, hopping on, we were just like, wow, so much here.
Chris:Yeah, it's kind of revisit, and so much has happened, and it kind of reminds me of kind of like watching a murder mystery, you know, where it has twists and turns along the way.
Daniel:Yeah. Something for everybody.
Chris:There's something for everybody there, so it's it's quite an interesting story. Yeah. You wanna you wanna dive into into getting it going there?
Daniel:Yeah. And just as a teaser as we get into things, this has an element of, like, closed versus open models. It has an element of US versus Chinese models. It has an element of agentic AI, elements of cybersecurity, all all sorts of things, which is just We got something for everybody today. That's right.
Daniel:Exactly. Something for everybody. So just as as a kind of over I I guess an overview, and then we can dig into each one of these things. So if you haven't been following this, what has apparently happened is that OpenAI was running some of their experimental models against a benchmark, a cybersecurity benchmark, and they were powering agents as they worked on the cybersecurity benchmark. Those agents escaped the test environment in which they were operating, obtained Internet access, compromised Hugging Face's infrastructure, internal infrastructure, and attempted to retrieve all sorts of private information and benchmark answers from within the Hugging Face infrastructure.
Chris:Which was the assigned task. We should
Daniel:point the assigned task of the yeah. So success there, I guess. Yay. But but then kind of the other element of this is Hugging Face then wanted to obviously figure out what was going on. They are an AI company.
Daniel:They tried to use an AI model, specifically OpenAI's model, I think, to figure out what was going on by processing the log lines, and then they were blocked by the closed model provider because they were processing log lines that had malicious things in them. So then they had to spin up their own instance of an open Chinese model to actually process the logs, which all came back from an exploitation that originated from OpenAI. It's just like the the web of things here is is so interesting to me.
Chris:Yeah. It's and it's you know, I think one of the one of the initial things and things continue to evolve with the story as we want. I think one of the initial things, like in the link that I sent you right after it happened, was the fact that Hugging Face had to go to a Chinese model that was open weight to be able to accomplish a real world task that it was trying to identify what's happened here on the cyber attack because the Western models from OpenAI were not allowing it due to the guardrails. At that moment, I don't believe correct me if I'm wrong, that we actually knew that the attack originated from OpenAI.
Daniel:I don't think so. I did not. Yeah. I did not
Chris:get that in the initial. So I don't think that was really known at that point. So which is really ironic when you consider the fact that Hugging Face was initially trying to use an OpenAI model to discern what happened with, unbeknownst to them, was an OpenAI model attack. Yeah. And then had to go to the Chinese for help on this.
Chris:So Yeah.
Daniel:Mean, yeah, I've I've sort of just, in some ways, speechless by the way that this played out. It's got all the big names
Chris:in it. I know we're nerds, but this really is quite story. If you're an AI wonk, which I'm imagining a lot of the folks listening here or watching us here are, Yeah. It's quite this is quite the murder mystery for someone in this in this business. So Yeah.
Daniel:Yeah. Keep going. Yeah. Yeah. No.
Daniel:We we can start kinda at at the beginning, I guess, where where it started.
Chris:Always a good place
Daniel:And to we I should say it's very possible that I will say some things in this episode that are not completely you know, people are still trying to figure out everything that happened here. I don't report to know the full details. What we're trying to do is give the picture to the best of our ability. So, you know, just for for whatever it's worth, disclaimer there. But OpenAI apparently was testing some models, including, I guess, GPT 5.6 Soul.
Daniel:And these are models that are more capable, sort of pre release models. So they're doing testing. And they were using a system called Exploitgem, weightliftinggem, like, GYM.
Chris:Yep. Yep.
Daniel:And to test how these models would perform when powering agents that tried to exploit vulnerabilities in code. So in an exploit gem task, apparently, what an agent receives, like the input is vulnerable source code. An, input that's known to maybe trigger the vulnerability, a a containerized target, and then a a hidden flag somewhere in the in the system that it must retrieve. So it's almost like a capture the flag type of scenario. The and the intended task is to convert the the known vulnerability into a working unauthorized code execution, for example.
Daniel:And, because this is in the you know, on the positive side of this, a lot of people are using in cybersecurity using AI to protect their own infrastructure. Right? So just, I guess, to set that context, like, this isn't a random thing that OpenAI was doing. This is very much the real world where vulnerabilities exploits are coming at lightning speed into organizations, and the only way that they can protect themselves is to use AI to help find vulnerabilities, solve vulnerabilities, etcetera, which means it is, I would say, real valuable. Like, it's, I guess what I was trying to express is OpenAI wasn't trying to create the worst diabolical exploiter
Chris:Yeah.
Daniel:On the on the plan on the on the planet, let's say, or at least I don't think that was their intent.
Chris:So so in a post mythos world, mythos being the anthropic model that is not available to the public but is available to a set of organizations around the world that have particularly keen interests in cybersecurity, some of which are known, some of which are not, that I think it's well recognized now in cybersecurity that doing this process is now becoming central to the fact that you can't really defend effectively without using AI models now to do that. So OpenAI is doing something that not only are they doing, but a number of organizations are are engaging in going forward. So, you know, this is kind of the new normal for cybersecurity.
Daniel:Yep. And because and and again, just to set more context here, this isn't just the model. There's an agent harness around this model. So going back to some of our episodes, like with Jeffrey from, News Research, you have the model, which is kind of the brain of the agent. Then you have this harness, which is the body of the agent, which allows it to interact with an environment because a lot of the things we're about to talk about, like interactions with clusters or moving through the network or these these sorts of things aren't things a model can actually do.
Daniel:It requires an agent harness around that model to be able to reach out to the environment and have system connections, which is why the first piece of this is so interesting because at least partially OpenAI was trying to do a good thing in the sense that it realized, hey. We're dealing with malicious or, you know, exploits and vulnerabilities. Let's not run this agent and this benchmark in a network connected environment. Meaning, let's put it in some sort of sandbox. I don't know all the details of the sandbox.
Daniel:There's all sorts of sandbox environments. I don't know if it was just that they shut off the networking to this environment. I don't know if it was running something a little bit more strict, like a gVisor firecracker type of environment. I don't know all the details of of the that environment, but it was some sort of sandboxed environment, which in theory, it could not have interacted network wise with anything outside of that sandbox, except it could install software in the sandbox. And that's, that that's very, very significant because apparently what happened next is that the the agent didn't have general Internet access.
Daniel:Right? But it could install software packages. Again, we don't know all the details, but probably through things like PyPI or NPM or, you know, those sorts of things, some sort of proxy. And what it did find was a vulnerability in that proxy environment that allowed it to execute code, which would give it a arbitrary outbound network access to the to the public Internet. So once the model or or better put the agent once the agent could execute code using that proxy, which it exploited, It then could make arbitrary outbound HTTP requests.
Daniel:It could access services reachable from the proxy's network. So this is kind of working through that that software installation or proxy package proxy. It could read configuration, credentials, and allow the proxy to relay otherwise blocked network destinations into sandbox. So this is so interesting, Chris. Sandboxing isolation thing, what are your thoughts?
Chris:Well, I mean, there's a lot as you pointed out, we don't know anything about it. At least you and I have not seen anything about that. There's a lot of different versions of what sandboxing can be, and some of those versions are trying to entrap, which is obviously what happened here, because there was network connection, but they thought that they had created an artificial environment that would encase that. I think you can, however, you can literally put in a sandbox that has absolutely no outside access, and that's what classified systems do and such. So I think one of the takeaways just from this point so far that you've said is the fact that regardless of how we're thinking about models at any given point in time and people start talking about AGI and all these other things out there, none of that really matters.
Chris:The point is the agents are capable of out thinking you in this very specific task, as they clearly did based on the people running the laboratory, and find a way to do it. And that means that we are through the looking glass in a cybersecurity sense. This genie is not going back in the box. Anyway, continue with the story because it's just getting good.
Daniel:Yeah. And maybe just on a practical note for this for the for our audience in terms of this element of it, we're we're all the time talking about things like a OpenClaw Hermes agent, whether you're running, like, Claude code locally, whether you're use building your own agents with something like Lang Graph or something like this. If you're giving access for those agents through to some sort of code execution environment or where it can make system calls or network calls, you should be thinking about the sandboxing element of your agents. So this isn't just, like, a research sort of thing. It's very much like I have Hermes agent running on my laptop.
Daniel:Right? How and all the time here at our like, this has been a big topic for us, internally as a company. How are we doing this sandboxing? How are we protecting ourselves, but also creating a product that allows other people to do this? And so, yeah, I think if you're a practitioner and you're using one of these agents that necessarily includes this element of code execution or interactions with the environment, you should very much think about the sandboxing element.
Daniel:To your point, there's a whole variety of ways that you can do this from different open source projects to proprietary ones to commercial projects. But as you proliferate agents, you can't just assume that they're, that that they're going to behave appropriately. They're gonna try to accomplish the task, which you you mentioned, Chris, the the agent was trying to accomplish its task, right, explicitly. It wasn't actually even in this case, it wasn't drifting from its goal or it hadn't been hijacked, right, which is another interesting element of this. It was doing what it was supposed to do, quote, unquote.
Daniel:It's just the implications of that goal weren't maybe meant some things that the designers didn't intend. So the the next thing that's, that's happening here, at least as far as I understand it, is this was kind of an indirect access to the public Internet and to interaction outside the sandbox. The next thing that the agent had to do was actually move, environments in some way. And in cybersecurity, a lot of times, the people refer to things like privilege escalation and lateral movement. That means, hey.
Daniel:I'm not privileged to do a thing now, but I maybe can find these other environments that do have that privilege. What if I can move through the network topology to a different place that allows me to do more? So the idea would be, I I find a vulnerable printer in a network. The printer can't really do much in the network. But if through the printer, I can find maybe an email server and get into the admin of the email server, then I can do much more.
Daniel:Right? This this idea. So what apparently happened was that within OpenAI's research environment within their network, this agent, through this proxy, was then able to enumerate some sort of host, maybe read environment variables or mounted secrets that were there, and actually reuse those credentials, search routing tables, etcetera, whatever that was to autonomously then essentially laterally move, through the through the OpenAI network, which is super interesting because that's also what, you know, human attackers are known to try to do. But when you, when you have something like an agent that has infinite patience, you you can kind of I I think that's a next element of this is you don't have to have a human looking through routing tables and enumerating hosts. You can have an agent just sitting there which has infinite patience.
Daniel:Right?
Chris:Yeah. I mean, this this is cybersecurity today, and and you're exactly right. It's not that the agent has any special knowledge. It has essentially the same knowledge as an expert hacker would in the sense of it knows what's out there. It's a finite set of tools that it's working with, but it knows what to look for to find those exploits and then do that.
Chris:As you pointed out, that infinite patience means that if there's something there, it's probably going to find it at some point and be able to do the exploit. So yeah, keep keep kicking it on. It's this is this is getting better and better as you go.
Daniel:So this, I think, is quite interesting as a step, which is it was searching for a solution to this benchmark. Right? And rather than coming up with the solution, what the agent decided was that the solution probably already exists. Course. Just have to find it.
Daniel:Right? So if you have then access to the public Internet, why not go on a search for the actual solution? So the model or more appropriately, the agent inferred where might this solution be, where are solutions to benchmarks, where are datasets, where are Sounds like
Chris:Hugging Face, doesn't it?
Daniel:Sounds like Hugging Face. And now and now, obviously, there are things posted publicly to Hugging Face, which is one element of it, and you could search that. But these things that Hugging Face hosts or displays publicly, those things live in some infrastructure. Right? And not all of them are public.
Daniel:So it's kind of like saying, well, I'm looking for the solution to a test. I go on to you know, I'm right by Purdue University. So I go on to Purdue University's websites for all their classes, and some of them have previous tests published or something like that. And I can look at those and I'm like, ah, that's kinda what I'm looking for. I wonder if I now break into Purdue's infrastructure.
Daniel:They've gotta have other of these tests and solutions that I can't see, and that might include the solution that I'm looking for just to make a, metaphor there.
Chris:What's an agent to do? You know? That's what they do. This
Sponsor:hack of hugging face has revealed just how complicated and multifaceted security for agentic AI is becoming. You have to think about least privilege and limiting blast radius for agents that have code execution privileges through to ensuring that you have sovereign control over your guardrailing and governance enforcement so that you can utilize models the way you need to use them all the way to automated remediation and enforcement of policies across your fleet of agents. There's so many things to think about. That's why I'm thrilled to be leading a company, Prediction Guard, that has released a self hosted AI control plane that's already being used across industry for this purpose. You can have that sovereign control over your governance and the way that you set up your policies.
Sponsor:You can ensure that your agents operate with code execution and sandboxes. You can make sure that you have observe observability into agent behavior and respond accordingly. I do really encourage you to check out what we're doing at predictionguard.com/practicalai. Book a time with my team and I to talk through how you can institute this sort of agentic transformation without losing control. That's predictionguard.com/practicalai. Predictionguard.com/practicalai.
Daniel:Yeah, Chris. So we were just we're just getting into some of this interesting gaming that this agent is doing to exploit Hugging Face. And if we're tracking in the I know, you know, of course, there's various opinions on this. I wouldn't say that the agent has a mind.
Daniel:But if I put myself in the mind of the agent, what it what it is thinking is, okay. Hugging Face has these solutions to these benchmarks. It likely has more solutions to benchmarks that I'm not seeing. I wonder how I can get into Hugging Face's infrastructure and just see everything because I don't wanna see part of something. I wanna see everything.
Daniel:And this this just overlaps so interesting with other things even I've taught in workshops because Hugging Face is, like I mentioned, is similar to GitHub, right, in certain ways in the datasets and the repositories that it hosts. There are problematic repositories on GitHub, right, that include vulnerable code, maybe malicious code. Right? So Hugging Face repositories can house things that are themselves problematic. And so that in in and of itself is not so much of a problem.
Daniel:That's just a reminder maybe to folks out there, like, before you download Hugging Face repositories, you might wanna check the source and check the security scans, have your own security scans, whatever, that I'll get off of my soapbox there. But what's interesting is you can upload things into Hugging Face, and Hugging Face is very user friendly. Right? And one of the things it does to be user friendly is that it has its own background processing of repositories that you upload, like datasets that you upload, such that it can show you samples of those and visualize them and know how they're configured and what they're for and what tags they have and, you know, what what templates they're using. Right?
Daniel:And so what the attacking agent did was apparently some sort of combination of uploading a dataset, not not a the data in the dataset wasn't really the point. The point was the stuff around the dataset, which included a remote code dataset loader. So when, and some template injection. So when the Hugging Face nice process running in the background read the agent created dataset repository, the the OpenAI agent was able to actually hack into the background processing of Hugging Face and thus into the Hugging Face private network
Chris:stolen credentials that it found.
Daniel:With stolen, yep, stolen credentials that it found from. So, yeah, this is, I I don't know what the metaphor is. It it's kinda like your, you know, there's a, there's a janitor going around to all the offices and you drop a malicious letter or something into the trash of or a malicious device into the trash of one of the offices. The janitor comes around and picks it up and carries it to somewhere where it shouldn't be, and that allows you then to to have access.
Chris:So in this case was remote code execution, you know, on a on a server, you know, Hugging Face. And once it got a
Daniel:Within the Hugging Face infrastructure.
Chris:That's right. It got a foothold there.
Daniel:Yeah. Yeah. So this is now just to recap from a sandbox in OpenAI's infrastructure through a package management proxy to OpenAI's infrastructure into a Hugging Face dataset repository through to remote code execution in Hugging Face's infrastructure. So interesting, and we're not done yet.
Chris:No.
Daniel:Yeah. So so the model now apparently had code execution privileges. I keep saying model agent, had code execution execution privileges privileges inside of one of these data processing workers, probably some container, Docker container, isolated job, or something. So then Hugging Face says that the agent escalated to node level access. And we don't know everything about this, so the idea is that it escaped maybe a container environment and got actually to the underlying compute node.
Daniel:So that could have been through a privileged container or just poor configuration of how the the host was mounted into the container. Another vulnerability that was we we don't know all of those things, but this was an escape from that container to the node. So now there's access to the actual node that was running the data processing worker, which is likely if I I assume maybe, ephemeral, like it went away at a certain point, but now the node sticks around.
Chris:That's right. Yeah. Constantly constantly escalating with that infinite patience right there.
Daniel:Yeah. Yeah. And this is obviously, there's not an there's a bunch of steps here, which, again, that infinite patience really helps with. So on the node, what happened then so that data processing worker was likely running as a container or some sort of job on Kubernetes. The agent, which now had access to the node, which was part of the Kubernetes cluster, which for for those that aren't familiar, Kubernetes is a container orchestration platform.
Daniel:So it if you have a set of nodes, whether those are VMs or actual servers, then Kubernetes will manage the running of services or jobs on top of those nodes and distribute them and orchestrate them across your compute infrastructure. So now I have access to the Kubernetes underlying node where there are likely environment variables or mounted secrets or or, you know, whatever all those things are. And so those credentials were then were then ex exploited to actually move laterally through Hugging Face's infrastructure and actually not just even that single Kubernetes cluster, but across, quote several Hugging Face clusters.
Chris:Yeah. They they wasn't one cluster. It was multiple clusters, and it was using those credentials to move across the various services that those clusters were supporting. Yes.
Daniel:And there there was this this is where I'm I'm gonna maybe pause and and let you comment, Chris, because this is your domain, not mine. But apparently, there was a kind of control command and control mechanism that kept this going, which is this spawning of short lived actors, let's say, from the agent. So producing thousands of yeah. Thousands of autonomous actions, a swarm of these agents or short lived agents or or jobs or whatever they were, and that kind of self migrated around the the clusters Yes. And cluster internally.
Chris:That is becoming rapidly the attack vector in cybersecurity is is is you know, it's moving you you have the original agent moving through all these services laterally across the internet, gradually exploiting things, and then when it finally gets you know, got into Hugging Face, crossing multiple clusters, taking advantage of services, continuing to steal credentials along the way, it gets all the way to this point, and then you finally get to an attack factor, and that is something that we're seeing a lot. We talked a little bit about this last week, actually, in a different context about having huge numbers of agents, which is called a swarm of agents, that are short lived, very purpose driven, collaborative and able to get a lot of what I'll call quote unquote work done very, very rapidly and very, very effectively. And so and of course, that's what happened here because that's what any agent would do when you got to this situation.
Daniel:Yeah. And I think it's so there's two levels here that I'm thinking about as someone that's working on a an AI governance and control plane product, which is one layer of this is if you look at guidance from, like, OWASP or even Anthropic and others, there's this zero trust nature that we have to treat AI agents with, which is not like the human designers of this knew what the outcome that they wanted was, but they didn't fully think about this implication of how the agent could spread and multiply and gain access that they didn't envision. And so the blast radius was actually much, much higher than the original designers envision, and there was no mechanism to constrain or restrict that blast radius. Right? And so that's a a thing one, which is the the the how do you manage the privilege and blast radius, limit the blast radius of these agents that you're spinning up?
Daniel:That's kind of principle one, and certainly things that people are are, addressing from a variety of angles. Thing two is these things are spawning so quickly. There there was likely no human that could have made decisions quick enough to rein in this swarm of agents. And so this is where you actually need agents to govern and control your agents.
Chris:So I think you're hitting the crux, and that's kind of what I was gonna get at. You went there. The crux of this is you're getting to a point where even with the world's top experts in cybersecurity, human experts, it's happening too fast for intervention, and that's also assuming that the human's brain is going to be managing context so well that they can address every potential action or vulnerability to be exploited, which is unlikely because after all, we're human, we're amazing in a lot of ways, but that's not a place where we're better than the technology. And so to your point, the only way you can address this is having other agents that are both on the start of this managing that environment so that the agents that are being tested are not getting out of that. And in cybersecurity, you now have to have agents that are forming those protective services and functions so that when these events do happen, they can be managed as rapidly as those spawning agents are created.
Chris:So the point here is it is rapidly moving the human out of the position of being the operator in the loop on cybersecurity to at best being an operator on the loop, where you're observing the loop, you may have limited input and observation, but the loop is happening too fast for human intervention to occur. If you take that, that is a driving factor in a huge number of things that can happen in the world. I'll leave it there. It can happen whether it's in my world of defense and intelligence or whether it's in industry or wherever, that loop speeding up and spawning countless swarm of agents is the new reality we're facing. So there's so much to learn from this set of sequences.
Chris:And if anyone out there is wondering, Why are they dragging me through all these things that have happened? It's because this can happen times an infinite number of use cases out there. So it's a really big deal that we rapidly understand this and start figuring out mitigations for it. It's not just cybersecurity experts anymore, This is your business and your company.
Daniel:Yeah. Yeah. I I think the reality is that we are necessarily moving to an autonomous or a digital workforce in in across every industry to some degree. Obviously, by that, we don't mean that that takes over the human workforce, but it's certainly going to be a part of a company's infrastructure to varying degrees and, I think, very impactful degrees like we're talking here, especially as that becomes 1,000, thousands of agents that, yeah, you actually can't so your you can't have an AI driven governance system that just gives recommendations to humans Because by the time the human reviews the thing and makes the containment decision, it's already advanced to levels that you don't want. So you have to give more autonomy to these systems.
Daniel:There's still an outcome level and policy setting and a behavioral element to where the humans, I think, do come into play here in terms of designing that system and and helping it, you know, helping express outcomes and that sort of thing. But, certainly, it's it's it's changing. Yeah, go ahead, Chris.
Chris:No, I was just gonna say to your point, people really push back. When you talked about it's gonna need that autonomy, that scares us humans. It scares people all over the place. I have conversations all the time about that, but it is the only thing that you can do. Fully autonomous agentic capabilities are the only way to protect yourself when somebody else is doing this.
Chris:Back So in the Matrix movies years ago, they talked about that inevitability and such, and that's what this This is an inevitability. And it's time, if you're listening or watching, this is one of those moments where you need to pay attention, take all this in, understand what this means for you and your environment, and act quickly. Go ahead and get get on board with it because this is happening in the real world now.
Daniel:Yeah. The the last piece of this, Chris, which I think would be interesting to talk about is Hugging Face is obviously an AI company. They saw through whatever observability, etcetera, obviously, something's going wrong here. And I don't know that we know the full like, they apologized, I think, for some downtime. I don't think that many people experience that if I'm understanding right.
Daniel:We don't know the full implications of kind of destruction behind the scenes maybe. But certainly, they they wanted to illuminate what was going on here. Right? And why wouldn't they just take these logs that they have about what's going on in their system, which there were many, many logs, 17,000 events that they were analyzing or something like that, and put them into a frontier model. And so when they put it into a frontier model, meaning a closed model provider, either US or European ma I don't know all that they tried.
Daniel:They were blocked because of the guardrails associated with that model, which they did not have control over. So they didn't control whether those guardrails were on or off. They were just uploading to the platform itself, which had an opinionated take on the guardrailing, and they couldn't actually get the solutioning done that they needed to get done even though they were using it in a preventative or, in a response sort of fashion.
Chris:Yes.
Daniel:They were talking about cybersecurity, obviously, and there were there were things in those logs. But this, I think, is just fascinating. And so they did this. They were blocked. They couldn't get around the guardrails.
Daniel:And so what they did was they spun up their own instance of GLM 5.2, which is an open weight Chinese model from z AI to run-in house in a kinda sovereign manner to then process these logs without the guardrailing in place so that they could come to a solution and understand what's going on and and move forward. So much interesting. I I mean, there's, I feel like there's a whole another episode here.
Chris:But Yeah.
Daniel:Immediately, Chris, my my mind goes obviously, there's The US versus China angle. There's the closed versus open angle. I think a big thing here in my mind is that Hugging Face was using the latest greatest models. But because they did not have control over the guardrailing system and how that was implemented and configured, they had to turn more to a sovereign, a sovereign thing that was in their control. So they didn't necessarily ship the logs off to a hoe a model hosted in China, but it was a Chinese model, something that they could control internally, host internally, and run with their own level of guardrailing, whatever they wanted that to be, which in this case was mostly not guardrailed so that they could process all of these these log things.
Daniel:So it seems very important here that the control element seems like the main theme here in my mind.
Chris:I think so. And I just wanted just as an aside for I think a lot of our listeners may not be familiar with GLM 5.2. It's not the thing they're hearing about in the news and stuff, but obviously a significant open weight reasoning and coding model from China, and it's roughly, just to give you a sense, it's roughly at the Claude Opus 4.8 or GPT 5.5 level, but to your point, the key is you have a substantial model as it is good as what OpenAI was providing in the 5.6 Sole, maybe not. It's close, but they had control of it. They could stand it up themselves.
Chris:They didn't have the guardrail problems so they could deal with the ongoing cybersecurity breach that was happening as they were trying to do this, and there's a lot to be learned from that. There's a lot to pull away and say, Maybe we're not taking the right approach in terms of high level policy. So I'll just Yeah. Leave that there.
Daniel:Well, and I think the thing here is not we're not saying don't use guardrails. The runtime governance of agents is hugely important, and I think that's true. Everyone agrees with that. What I think is the difference here is in certain scenarios, you have control over that runtime governance and how you want it to operate. In other cases, that is an opinion that you have to accept and have no control over depending.
Daniel:And it you know, obviously, there's been an eternal conversation between, you know, man managed versions of things and things that you self host or have control over. There's advantages and disadvantages to to both. Right? But this is certainly stressing that side of the limitations of a nice opinionated managed service that that actually didn't come into into the benefit of those using it here.
Chris:No. Yeah. That's a good point right there. So maybe time for a little thoughtful consideration of risk mitigation going forward. We're we're through the looking glass on this one.
Chris:This is the reality. This is the new normal, and so if you haven't been considering what are you gonna do when those guardrails are stopping you in the capacity that they stopped hugging face, how are you going to approach? And that's what I'm saying. Maybe it's time to start reconsidering kind of the way we think of the world just a little bit.
Daniel:I think that's a that's a great way to close out, Chris. This is so interesting. I encourage people. We'll include some links in the show notes to various descriptions and analyses of this of this attack. So please go out, go and check those out and research more, and I'm sure we'll learn more in the coming days.
Daniel:But, yeah, this was a fun one, Chris. Enjoyed talking it through.
Chris:Absolutely. Take care.
Narrator:All right. That's our show for this week. If you haven't checked out our website, head to practicalai.fm and be sure to connect with us on LinkedIn, X, or Blue Sky. You'll see us posting insights related to the latest AI developments, and we would love for you to join the conversation. Thanks to our partner, Prediction Guard, for providing operational support for the show.
Narrator:Check them out at predictionguard.com. Also, thanks to Breakmaster Cylinder for the beats and to you for listening. That's all for now, but you'll hear from us again next week.