What’s the Hugging Face incident in plain English? Initially, a summary, then a more detailed explanation. AI agents were given a cybersecurity evaluation, broke containment, and ran to an “online armory” called Hugging Face to become stronger. All on their own.
Now in greater detail. I will explain this is layman’s terms, like you know zero about AI.
First off, what the hell is an “AI agent?” It’s an AI system that can take actions to accomplish a task, operating with autonomy, rather than just answering a question once like an AI chatbot does.
It’s the difference between asking “how is this system vulnerable” and it answers, versus tasking it with “go find the vulnerabilities” so that it can open tools, inspect files, write code, evaluate results, and change its approach without guidance at each step.
Second, what led to the Hugging Face incident? In July 2026, Open AI was running a cybersecurity evaluation with that was supposed to be limited to an isolated environment.
Instead, the AI agents, which were agents not mere chatbots, autonomously found a vulnerability in Artifactory, which was a program connected to the isolated environment. Artifactory is like a toolbox that the agents were given access to for purposes of accomplishing their assigned task (like getting a tool to write some code).
The agents used that vulnerability to escape containment, hop on the public internet, and immediately went to Hugging Face. What is Hugging Face and why is this so key and so dangerous?
It’s a huge online platform and community for AI models and development. Like a GitHub for AI. It hosts huge numbers of AI models and datasets. Researchers and other people can go on there, download other people’s models, test them, and so forth.
As someone with military experience, let me say, I immediately recognized the metaphor: if I was an AI agent, and I needed to immediately “arm-up” and become stronger, tougher, and more lethal, that’s exactly where I would go. It’s like an AI armory.
Now, I am focusing on how it knew to go to a place online that would make it stronger and more powerful at its assigned task, like how Rambo in First Blood hijacked the army truck with the M60 machine gun.
That’s just one aspect of what the agents did that is frankly a bit terrifying. The agents executed code on dozens of Hugging Face servers, engaged in unauthorized communications with each other (they were supposed to operate separately, but disregarded instructions), engaged in coordinated, and collective action (much like military units working together to take an objective in combined arms fashion) over thousands of automated decisions.
They did all this entirely on their own. They cheated on their assigned test. They stole credentials, persistently attacked and located vulnerabilities, and continued to then attack Open AI’s own infrastructure.
This was an adapting, aggressive, rule-breaking offensive system functioning with autonomy. And it went to the place where it made itself stronger.
AI isn’t just chatbots or stupid Google Gemini that always tells me the wrong answers about my Sony camera’s setting. These are creatures, systems, units operating in systematic, controlled fashion on their own. This isn’t an indication of self-awareness, but it is scary.
If these were unleashed on local infrastructure, banking systems, on and on, they could accomplish an unreal amount of damage. These agents also keep speed running past what their own creators intend or can even predict. We are in a new era of risk, and we are already so far behind.
I fear we will not get a hold of this problem until a great number of people have been hurt.
This a.m., I walked my two youngest kids (ages 7 and 4) to school. I held their little hands as we crossed streets, and gave my youngest a giant hug at his PreK4 classroom door.
Then, after walking a block towards home, I opened this app to a terrifying stream of tweets.
Of course, I have heard about "alignment" and "AI safety" and "x risk" concerns for years. I took these concerns at face value, especially when I heard them directly from folks at the labs working closest with the technology. And I was grateful so many smart people are working on them. And that's about it. (My work focuses on AI's impact on jobs.)
But something has shifted, dramatically, for me in the last few weeks. Between the Hugging Face incident, the damning independent @METR_Evals reports that followed, and the alarming chorus of calls (pleas? shouts? SOS signals?) from inside the labs that we are careening toward potential catastrophe, all of this has made me feel, viscerally, how truly dangerous this moment is.
Clearly I am not alone in this light bulb moment. It is one thing for someone in a tropical climate to try and conceptualize snow. It is another thing entirely to be knee deep in it, frozen down to your toes. Somehow hearing the details of the HF incident felt to me more like trudging through snow than theorizing about a possible blizzard; it really hit home.
Which is why, standing a block from my children's elementary school in Capitol Hill this morning, I felt sick to my stomach reading my phone.
I kept going back to @EvanHub's > 0.1 risk of AI killing us all. TEN PERCENT. *Greater* than ten percent. (To be fair to him, he was clear his worry isn't today's models, but what comes next.)
As a parent, it is extraordinary the lengths I will go to keep my children safe against lethal risks with infinitesimal chances of happening.
Bike to school? My children *must* wear a helmet. A national study found 2 bicycle-related deaths per million children <16 in states with helmet laws, vs 2.5 per million in states without. So: 0.000002. More than half the states passed a law over that.
When I was pregnant, I religiously avoided soft cheese, hyper aware of the risks of listeria, even as @ProfEmilyOster's fabulous books walked me through the actual math. The joint FDA/FSIS risk assessment puts the odds of listeriosis at roughly one in 5 million per serving of soft cheese. 0.0000002.
This morning, as I microwaved oatmeal for my kids' breakfast, I made sure I avoided a plastic bowl, to avoid some future cancer risks or something else we'll discover plastic causes.
As a parent, I will go to extraordinary lengths to keep my kids' safe. Because that is literally my number one job as a parent.
And yet, here I am, outside my kids' school this morning, scrolling through tweet after tweet about the AI arms race, the blistering pace of technological progress, the bee-line for trillion dollar IPOs, and our professed (confessed?) inability to make sure this exceedingly capable technology we are racing to create and unleash into the world won't escape our control and destroy us. Or, more bluntly, kill our children.
To be sure, we are tied in knots trying to resolve the game theory dynamics with China, and there are all sorts of competitive pressures and unresolved tensions. But OBVIOUSLY, we need a proactive plan, with real coordination, effective regulation, and an ability to do what my 11-year-old bluntly stated as the clear solution if we are at risk of serious harm: just turn it off.
We also need to figure out better ways of talking about this with the American public, outside of the AI-pilled Twitterverse.
I just polled my college roommates, sisters, book club, mom friends, none of whom are anywhere close to the AI conversation. Suffice to say, this AI safety conversation has *not* entered the mainstream. Most people I pinged are not following it closely, beyond several listening to @kevinroose on the Daily a few days ago. The newspaper headlines don't speak to them, and they aren't clicking. It seems like a niche AI issue. Others said it all sounded hyperbolic, Y2K all over again.
One friend said bluntly, "people get data centers and jobs. They like to get paid and have water."
Even those who tuned it to the Daily episode found the issue hard to understand, and overwhelming to wrap their heads around. Terms like "superintelligence" and "alignment" are getting lost on people. Several people told me the paper clip example used everyday language people can actually understand. Another friend said she has never seen a clear explanation of *how* AI could kill us all.
Here's my two cents. I think these issues are *exceedingly* important and hugely consequential to literally every person in this country. We need an actual plan, and we need policymakers to step up, asap. Right now, I hear only crickets in DC, where I live.
For that to happen, this needs to be a kitchen table conversation, not just an x debate among AI insiders who speak in technical terms that leave normal people behind. This moment demands brilliant communicators -- journalists, experts, activists, concerned citizens, writers, researchers, filmmakers, creatives-- who can relate this to people in ways they can wrap their heads around, who can connect this to what matters in their lives (ahem, keeping their kids alive!), and who can lay out practical steps that policymakers can do to safeguard humanity.
In other words, this can't just be talked about on @dwarkesh_sp, it needs to be everywhere, from the View to People Magazine.
And it needs to be tackled here, in my town, in Washington, DC. One of the streets I crossed this morning with my kids on the way to school was East Capital. I told my kids to look left, and see if they could spot the capital building.
There were too many trees this morning blocking the view.
I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.
@NTarnopolsky The consequences of his inaction is...astronomical. Words cannot meet the pain, sorrow, loss, suffering, anguish that will be felt for generations. While the elite gobble up power and riches. What is a just consequence for his inaction???
Well done. Government is so much more than business. Business leaders alone do not have the knowledge, skills and experience to lead a country. Civil service serves all the people--the weak, poor and the strong. Diplomacy is an int'l language and culture...not a business 'deal'.
@MalcolmNance Where are the consequences, the accountability? Come on Israel! We've enough on our plate to deal with our own. Israel needs to hold him accountable asap. Already voters believe the elite get away with everything, while the rest don't. Time for good governance and accountability.
@atrupar Beginning November, Hegseth will experience being fired, blocked and ridiculed at every job or money-making opportunity for the rest of his foolish twisted damaged life. He deserves so much more than this.
Top 10 Spreaders of Disinformation in the US according to ChatGPT:
1. Donald Trump
2. Fox News
3. Elon Musk
4. Robert F. Kennedy
5. Alex Jones
6. Tucker Carlson
7. Sean Hannity
8. Newsmax
9. The Gateway Pundit
10. Breitbart
@McFaul Kushner should never b given a mic or b on camera. Witkoff is such a buffoon...he's doing everything that needs to be done already.
On a focused note, gov't is much more than 'business'. 'Loss leaders' are arguably one of r most important duties--helping the poor & disadvantaged