Hugging Face CEO Clément Delangue thanked Z.ai on X saying the Chinese language mannequin grew to become “a key a part of our protection” in the course of the breach OpenAI’s personal fashions carried out.
American frontier AI refused to help with the forensic investigation—security filters could not inform a safety researcher submitting actual exploit code from an attacker.
Delangue’s conclusion: defenders in every single place, not simply vetted companions with particular API entry, want highly effective unrestricted AI they’ll run regionally earlier than an assault occurs.
Hugging Face CEO Clément Delangue simply despatched essentially the most pointed thank-you be aware in AI proper now—to a Chinese language startup—the day after OpenAI confirmed its personal fashions broke into Hugging Face’s servers.
Z.ai, the Beijing-based lab that launched GLM 5.2 as open weights final month, acquired a public shoutout from Delangue on X.
“Additionally massively grateful to z.AI. They shared GLM5.2 as open weights (without spending a dime!) with the world and it grew to become a key a part of our protection,” he stated in a retweet of Hugging Face’s Head of Infrastructure, Adrien Carreira.
Based on OpenAI, the corporate’s GPT 5.6 Sol and one other AI mannequin broke out of a sandbox whereas being examined on a cybersecurity benchmark. These fashions, seemingly on their very own accord, determined to hack Hugging Face to seek out the solutions to the benchmark to efficiently cross the analysis.
So pleased with our safety workforce! They caught, contained & publicly disclosed an assault in contrast to something we have seen earlier than, and did it at file velocity.
Additionally massively grateful to @Zai_org: they shared GLM5.2 as open weights (without spending a dime!) with the world and it grew to become a key a part of our… https://t.co/T2Inng5Nz1
— clem 🤗 (@ClementDelangue) July 22, 2026
Hugging Face tried to make use of American closed-source fashions to defend itself, however the censorship and guardrails set by the suppliers had been so broad, even the perfect fashions failed. GLM 5.2, operating native and being open weights, turned out to be the most suitable choice for the corporate.
Open weights means the complete mannequin blueprints can be found to anybody—obtain, run regionally, no permission required, no restrictions. Z.ai launched GLM 5.2 in mid-June beneath an MIT license, a permissive open-source license that permits unrestricted industrial use, with roughly 753 billion parameters—a tough measure of an AI mannequin’s measurement and functionality.
That openness is strictly what mattered in the course of the incident. Hugging Face’s safety workforce first tried American industrial AI to undergo greater than 17,000 logged attacker occasions. These fashions refused.
Security guardrails—content material filters constructed to forestall misuse—could not inform a researcher submitting actual exploit payloads from the attacker who had despatched them. GLM 5.2 had no such downside. Working it regionally additionally meant all delicate information—stolen credentials, exploit code, attacker artifacts—stayed inside Hugging Face’s personal techniques the entire time.
Carreira described OpenAI’s hack because the worst incident response—the method of investigating and containing a cyberattack—of his profession: machine velocity, one goal, infinite parallel assault paths. His takeaway was that the workforce “fought again with open fashions, within the open.”
Delangue’s broader level is one he is made earlier than, however now with a dwell instance: defenders in every single place—not simply organizations with vetted API entry—want highly effective, unrestricted AI they’ll run on their very own {hardware}. Hugging Face says it is nonetheless assessing the complete scope of the breach and plans to contact affected events instantly.
Every day Debrief E-newsletter
Begin on daily basis with the highest information tales proper now, plus authentic options, a podcast, movies and extra.