By Justin Sherman | Analysis | July 23, 2026
The OpenAI-Hugging Face incident entailed a US model going out of control, hacking into an American company, with a Chinese open-source model offering a defensive solution for cybersecurity. Image: Jernej Furman from Slovenia, CC BY 2.0
On Tuesday, OpenAI announced that last week two of its AI models had gone rogue and hacked into Hugging Face, an American company maintaining a vast, open repository of models, datasets, and applications for AI research and development. The models in question were GPT-5.6 Sol and another “even more capable” model that OpenAI has not yet released.
According to OpenAI, the models found a vulnerability in their sandbox testing environment, escaped, and targeted Hugging Face (named after the hugging face emoji) to get information on how to successfully pass evaluation tests—essentially, trying to find the answers to the tests that OpenAI staff were putting them through. Hugging Face detected and stopped the activity and is now collaborating with OpenAI on an investigation of the incident.
To detect and respond to the breach, Hugging Face used an open-source Chinese model, Z.ai’s GLM 5.2. This was not for a lack of trying American ones: Hugging Face first leveraged unnamed frontier models, but they “did not work.” The providers could not distinguish between launching an attack and responding to one, so their guardrails blocked Hugging Face from submitting real attack commands, exploit payloads, and command-and-control artifacts it needed to have the models analyze. As the company wrote, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.”
Beyond underscoring the potential impact of agentic systems on cybersecurity, this incident highlights that a zero-sum security view of US-China AI interconnection is reductive—and potentially counterproductive—for American security. Currently, there are few restrictions on accessing American models outside of the United States and Chinese models inside the United States. Even if policymakers do wish to restrict the reach of certain, Chinese AI-related components that present unacceptable security risks, depriving American companies, universities, and other actors of the ability to access, test, and potentially even leverage Chinese open-source capabilities for their own security can come with unforeseen costs that are not evident until an incident is unfolding in real-time.
There is much debate lately in Washington and other national capitals about AI interconnectedness. Privacy regulators worry, rightfully so, about how companies are collecting data, from which countries or jurisdictions that data is sourced, and what consent and privacy measures exist around it. Industrial policy advocates in the United States evaluate the efficacy of the CHIPS Act in creating semiconductor jobs at home and bringing more technology and facilities in the country—and, implicitly, out of China and proximate areas of the globe. National security professionals likewise debate how cross-border interdependence in parts of the AI stack, including between the United States and China, can create security risks that demand export control responses, bilateral dialogues on strategic risk reduction, and other measures.
However, the debate is often compressed into simplistic headlines and catch phrases related to the US-China AI arms race. One day, the United States is said to be beating China in AI; on another day of the week, China is beating the United States. More American AI is good for the United States; more Chinese AI is bad for US security. Look no further than the years-long dance of analysts hoping for a single variable that will help them decide which nation “holds” the “lead” in AI. Nearly a decade ago, conventional DC policy talk held that data quantity mattered most, even though calling data “the new oil” ignored other simultaneously important factors like data quality, data diversity, compute access, and human talent. Nowadays, the complexities of US-China interconnection get boiled down to other data points, such as which nation awards more STEM doctoral degrees or how many people download open-source models from one country or the other.
The OpenAI-Hugging Face incident instead entailed a US model going out of control, hacking into an American company, with a Chinese open-source model offering a defensive solution for cybersecurity. A simplistic view of US-China AI relations would maintain that Chinese AI models could come with backdoors, where a bad actor can exploit pre-inserted flaws down the line, (which is true) or undercut the competitiveness of American AI models (which is also true) and should therefore be banned from the United States. In this scenario, Hugging Face would not have been allowed to access Z.ai’s GLM 5.2—only whichever unnamed US frontier models it originally tried to use for its own defense.
Putting aside the regulatory questions about such a restriction, the outcome would be US policy depriving an American company, and an important and innovative one at that, from defending its own networks. The outcome would be assuming that available American AI models were more than enough for the American company to protect itself (which was clearly not the case). This hypothetical scenario would also be a clear signal to the world’s malicious cyber actors (including those in China) that American companies would not be arming themselves with the most robust capabilities to detect, mitigate, and respond to real-time security incidents.
Ironically, the United States is well behind many other countries in data privacy regulation, cybersecurity regulation and mandatory standards, and regulation of AI technologies and applications. But in this recent attack, an American company (Hugging Face) trying to stave off an attack from the rogue agentic systems of another (OpenAI) found that a third US company (unnamed) had too many guardrails in place to be valuable in its own defense. So, it turned to a Chinese open-source model whose security value proved much greater. Assumptions about national origin, guardrail robustness, and security utility would obscure this critical insight.
Two things can be true at once: Many Chinese government uses of AI technologies present serious risks to US national security (to say nothing of human rights in China), especially as the Chinese government leverages agentic systems to conduct offensive cyber operations and control unmanned aerial vehicles for combat. It is also true that US-Chinese touchpoints on AI research and development can yield many benefits for both nations, whether on self-driving car safety, climate modeling, or cross-border educational exchange. Security risks and opportunities from US and Chinese AI systems are intermingled, not mutually exclusive.
National security policymakers taking away lessons from this incident should resist the temptation to sort models’ national security impact into simplified buckets of good and bad based on their country of origin. As policymakers debate restricting the outbound flow of US AI technologies (a highly dubious exercise) and limiting the inflow of Chinese AI models, they should instead consider different scenarios and contexts in which AI capabilities from other countries could present different opportunities and risks. For example, this should include interrogating the assumption that American AI models are in fact practically useful for cyber defense, in the private sector, in operational contexts; clearly, this may not always hold true.
Policymakers should also leverage empirical evidence wherever possible to further underpin claims of where American or Chinese models may be better or worse for both cyber offense-defense (such as the ability to help carry out or mitigate attacks) and for cybersecurity in general (like susceptibility to hijacking or inclusion of vulnerable code). In particular, debates about American and Chinese AI models would benefit from greater use of empirical AI benchmarks based not on abstract theories of cyber operations but on the knowledge and experience of hands-on-the-keyboard and other experienced cybersecurity practitioners.
A more nuanced assessment of how American and Chinese AI models impact US cybersecurity may not make headlines. But it will certainly make for better policy—and simultaneously ensure that the state-of-the-art in American cyber capabilities and the state of cybersecurity across the public and private sectors can evolve simultaneously against a persistent Beijing threat.
The Bulletin elevates expert voices above the noise. But as an independent nonprofit organization, our operations depend on the support of readers like you. Help us continue to deliver quality journalism that holds leaders accountable. Your support of our work at any level is important. In return, we promise our coverage will be understandable, influential, vigilant, solution-oriented, and fair-minded. Together we can make a difference.
Keywords: AI, AI race, Hugging Face, OpenAI, US-China AI race, artificial intelligence, cybersecurity
Topics: Artificial Intelligence, Disruptive Technologies