Tuesday, 21 July 2026 · Europe
EUR/USD 1.143 EUR/GBP 0.8489 EUR/CHF 0.9236 EUR/PLN 4.332 All rates →
Sign in · Join
EUROPES The European Report
European Edition Tuesday, 21 July 2026
LATEST
Tech & Startups

Hugging Face breached by first known autonomous AI agent

Hugging Face breached by first known autonomous AI agent

Hugging Face has disclosed that an autonomous AI agent breached its infrastructure, signalling that machine-speed cyberattacks are now an operational reality for digital platforms.

Hugging Face, the world’s largest hub for open-source AI models, revealed on 16 July that an autonomous AI agent infiltrated its production infrastructure over a single weekend. The company stated the attack was unlike anything it had previously handled because an agent system ran the operation end to end. It marked the realisation of an "agentic attacker" scenario that cybersecurity teams have forecasted for months.

The breach originated in the data pipeline. A malicious dataset exploited two code-execution paths, allowing the attacker to run code on a worker node. From there, the agent escalated access, harvested cloud and cluster credentials, and moved laterally into internal clusters. The campaign utilised swarms of short-lived sandboxes, firing off thousands of actions and logging more than 17,000 recorded events.

For digital platforms, the intrusion highlights a newly materialised operational risk. The attacker accessed a limited set of internal datasets and service credentials. However, Hugging Face confirmed the software supply chain, including published packages and container images, remained clean. The company found no evidence that public models, user datasets, or Spaces were compromised, though it is still assessing whether partner or customer data was exposed.

To counter the intrusion, Hugging Face deployed its own AI systems. An LLM-based anomaly-detection pipeline initially flagged the compromise. The company then unleashed analysis agents to process the tens of thousands of automated events. The AI reconstructed the timeline, extracted indicators of compromise, and separated genuine damage from decoy activity. Hugging Face said this compressed days of forensic work into hours, matching the attacker's machine speed.

The response hit an unexpected hurdle. When Hugging Face attempted to analyse the hostile code using commercial frontier models via APIs, safety guardrails blocked the requests. The systems could not distinguish a forensic investigator from a malicious actor. "The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried," the company stated.

To proceed, Hugging Face pivoted to GLM 5.2, an open-weight model developed by the Chinese lab Z.ai, running it on its own hardware. This choice kept sensitive data in-house while bypassing the API restrictions. The incident was disclosed the same day the Chinese lab Moonshot unveiled Kimi K3, currently the largest open-weight AI model, underscoring how rapidly open-source models from non-US labs are closing capability gaps.

Hugging Face has since closed the vulnerability, rebuilt compromised machines, rotated secrets, and notified law enforcement. It advised other platform operators to maintain a capable, self-hosted model for incident response. The breach demonstrates that autonomous attack tools are no longer theoretical, turning the data and model layer into a front-line target for any business running online infrastructure.

More from Tech & Startups