In brief

  • Hugging Face CEO Clément Delangue thanked Z.ai on X saying the Chinese model became "a key part of our defense" during the breach OpenAI's own models carried out.
  • American frontier AI refused to assist with the forensic investigation—safety filters couldn't tell a security researcher submitting real exploit code from an attacker.
  • Delangue's conclusion: defenders everywhere, not just vetted partners with special API access, need powerful unrestricted AI they can run locally before an attack happens.

Hugging Face CEO Clément Delangue just sent the most pointed thank-you note in AI right now—to a Chinese startup—the day after OpenAI confirmed its own models broke into Hugging Face's servers.

Z.ai, the Beijing-based lab that released GLM 5.2 as open weights last month, got a public shoutout from Delangue on X.

“Also massively grateful to . They shared GLM5.2 as open weights (for free!) with the world and it became a key part of our defense,” he said in a retweet of Hugging Face's Head of Infrastructure, Adrien Carreira.

According to OpenAI, the company's GPT 5.6 Sol and another AI model broke out of a sandbox while being tested on a cybersecurity benchmark. These models, seemingly on their own accord, decided to hack Hugging Face to find the answers to the benchmark to successfully pass the evaluation.

Hugging Face tried to use American closed-source models to defend itself, but the censorship and guardrails set by the providers were so broad, even the best models failed. GLM 5.2, running local and being open weights, turned out to be the best option for the company.

Open weights means the full model blueprints are available to anyone—download, run locally, no permission required, no restrictions. Z.ai released GLM 5.2 in mid-June under an MIT license, a permissive open-source license that allows unrestricted commercial use, with roughly 753 billion parameters—a rough measure of an AI model's size and capability.

That openness is exactly what mattered during the incident. Hugging Face's security team first tried American commercial AI to go through more than 17,000 logged attacker events. Those models refused.

Safety guardrails—content filters built to prevent misuse—couldn't tell a researcher submitting real exploit payloads from the attacker who had sent them. GLM 5.2 had no such problem. Running it locally also meant all sensitive data—stolen credentials, exploit code, attacker artifacts—stayed inside Hugging Face's own systems the whole time.

Carreira described OpenAI’s hack as the worst incident response—the process of investigating and containing a cyberattack—of his career: machine speed, one objective, endless parallel attack paths. His takeaway was that the team "fought back with open models, in the open."

Delangue's broader point is one he's made before, but now with a live example: defenders everywhere—not just organizations with vetted API access—need powerful, unrestricted AI they can run on their own hardware. Hugging Face says it's still assessing the full scope of the breach and plans to contact affected parties directly.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.