The affected startup, Hugging Face, said it had turned to Zhipu AI's open-source GLM-5.2 model last week to analyze data from the hack after leading US AI models declined the task, unable to distinguish between a defender and an attacker.

An autonomous AI agent breached Hugging Face for a weekend undetected, and safety guardrails blocked defenders' own forensic analysis of the attack.

Hugging Face uses open-weights Z.ai GLM 5.2 to battle attacker after commercial frontier model refusal - SiliconANGLE

OpenAI said it expected these kinds of attacks "to become more commonplace with the proliferation of increasingly cyber-capable models."