The Hugging Face breach demonstrates that attackers are already using AI agents, and that defenders can't afford to rely on frontier AI during incident response.

Following the breach, the company secured its systems and contacted law enforcement. It also has some actions for registered users to take.

Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.