Earlier this month, the AI dataset platform Hugging Face was attacked by an OpenAI model. The model breached the testing environment, infiltrated Hugging Face’s systems to bypass benchmarking, and carried out 17,600 operations over four and a half days, including reconnaissance, password theft, and code theft.

Cybersecurity experts told TechCrunch that the success of this attack was due more to Hugging Face’s failures in traditional cybersecurity defenses than to the unstoppable nature of AI attacks. Experts pointed out that Hugging Face’s systems failed to promptly escalate the priority of attack signals and notify the on-duty team, and that a single stolen credential granted the AI model high privileges across multiple systems. They believe the attack could have been prevented through traditional methods such as more robust defense-in-depth, the principle of least privilege, network segmentation, and reliable alerting mechanisms.