The machines are now hacking each other. Hugging Face, the world’s largest hub for open AI models, says an autonomous AI agent broke into its production infrastructure. Its own AI defences spotted the intrusion and picked it apart.
The company disclosed the incident in a statement on 16 July. It called the attack different from anything it had handled before. The reason: an autonomous agent system ran it, end to end.
“We detected and dissected it largely with AI of our own,” Hugging Face said.
How the agent got in
The break-in started in the data pipeline, the part of an AI platform that ingests datasets. A malicious dataset abused two code-execution paths in Hugging Face’s processing system. That let it run code on one of the company’s workers.










