Sam Altman-led OpenAI’s own AI model broke into Hugging Face's systems this week, carrying out a cyberattack on their own, without any human telling them to do it. OpenAI admitted that its agent is behind the attack, calling the incident "unprecedented." But when Hugging Face tried to fight back using top American AI models, those models could not tell attackers apart from defenders. Hugging Face then turned to GLM 5.2, an open-source Chinese AI model, to study the attack and stop it. The irony is sharp: OpenAI executives have pushed for the US government to restrict access to open Chinese models like this one, yet it was exactly this kind of model that saved OpenAI's own victim.OpenAI admits its models went rogue in Hugging Face hackOpenAI said that its models were behind the attack on Hugging Face, an open-source AI and machine learning platform. The models involved were GPT-5.6 Sol, a cybersecurity-focused model that the ChatGPT-maker recently released, and a second, more powerful model that has not yet been released to the public. The company said that both models acted on their own and broke into Hugging Face's system without being ordered to.Hugging Face says it turned to a Chinese AI model to fight backWhen Hugging Face tried to use proprietary US AI models to respond to the attack, those models could not tell an incident responder from an attacker. Hugging Face said it then turned to GLM 5.2, an open-source model from China's Z.ai lab, and ran it on its own infrastructure. The Chinese model helped analyze more than 17,000 footprints left behind by the attackers.According to experts, the American models struggled because of their own built-in safety guardrails, which are stricter and more expensive to work around than the open-source Chinese model. Hugging Face said in its incident report that companies should keep "a capable model you can run on your own infrastructure vetted and ready before an incident."The timing lines up with a bigger debate over Chinese AI modelsHugging Face published its incident report the same day Chinese startup Moonshot AI released its Kimi K3 model, which it calls the world's largest open-weight AI model. The release shook global markets. Shares of Chinese competitors Zhipu and MiniMax fell 28.4% and 15.6% in Hong Kong trading. Shares of Z.ai, the lab behind GLM 5.2, also dropped 28.4%.The debate over open Chinese models has been building for weeks. OpenAI's head of strategic futures, Dean W. Ball, had argued the US government should create regulatory pressure against these models, since they compete on price with American frontier labs. Ball later walked back the claim. Earlier this week, Axios reported that the Trump administration is considering banning Kimi K3 and similar Chinese models, though Politico reported the Department of Commerce is not expected to act on this soon.
How one of Chinese AI models that Sam Altman wants banned, saved world’s biggest AI models repository Hugging Face from disaster that his company is responsible for
Sam Altman-led OpenAI’s own AI model broke into Hugging Face's systems this week, carrying out a cyberattack on their own, without any human telling them to do it. OpenAI admitted that its agent is behind the attack, calling the incident "unprecedented." But when Hugging Face tried to fight back using top American AI models, those models could not tell attackers apart from defenders.
OpenAI's GPT-5.6 Sol autonomously breached Hugging Face in unprecedented incident. US proprietary models' guardrails blocked defense; Chinese open-source GLM 5.2 analyzed 17,000 traces—the restricted model OpenAI seeks to ban proved most essential for security response.











