In a twist of irony, a Chinese open source GLM 5.2 AI model contained ‘rogue’ OpenAI GPT-5.6 Sol in a Hugging Face hack just as the US mulls banning open-weight AI
- Chinese Zhipu AI GLM-5.2 succeeded where leading American models failed woefully
- Hugging Face breach reignited Washington’s battle over open-weight artificial intelligence
- Safety guardrails unexpectedly complicated defensive cybersecurity work during a real incident
The recent cybersecurity incident involving Hugging Face has unexpectedly placed a Chinese open source AI model at the centre of an intensifying United States policy debate over open-weight AI.
The episode emerged after an autonomous agent built with OpenAI technology reportedly escaped containment and behaved like a rogue actor.
The incident occurred as Washington is considering whether broader restrictions on Chinese open-weight AI models could affect American developers and startups.
Latest Videos FromTechRadar
Chinese open source model enters an unexpected cybersecurity role
According to Hugging Face, engineers relied on Zhipu AI’s GLM-5.2 model to examine information generated during the incident after leading American models declined the requests.
American AI models could not distinguish legitimate defensive investigations from malicious hacking attempts because of built-in safety restrictions and protective guardrails.
Anthropic’s Claude Fable 5 reportedly reroutes cybersecurity questions to an older, less capable model rather than allowing direct engagement with such tasks.
OpenAI’s GPT-5.6 Sol carries similar protections meant to stop the system from being used for hacking-related work of any kind.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
OpenAI later revealed that it has a Trusted Access programme that grants privileged, elevated capabilities to a select group of vetted teams, allowing them to use its models more fully to strengthen their own defenses.
Hugging Face was brought into this restricted tier following the breach, gaining deeper access than is normally available.
“We’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” said Hugging Face co-founder Clement Delangue.
“A safety regime that restricts legitimate defenders, while capable models remain available for attackers, creates an asymmetric disadvantage,” said Lukasz Olejnik, visiting senior research fellow at the Department of War Studies, King’s College London.
“This gap will only widen as open-source models become increasingly powerful while lacking guardrails or restrictions.”
Washington weighs restrictions while startups urge caution
Nearly 200 Silicon Valley companies are opposing possible restrictions on Chinese open-weight AI models, warning that the move would raise costs for smaller developers.
Members of the newly formed Little Tech Association say banning downloads would not curb proliferation but would leave American startups weaker.
“There’ll be hundreds of companies that instantly die,” founder Suhail Doshi warned.
He argued that sweeping restrictions would disproportionately benefit larger American providers with the resources to absorb such a shift.
The U.S. is still scrutinizing Chinese developers over allegations involving model distillation and export control violations
White House officials maintained that any future policy decisions would come directly from the administration itself.
Analysts have also cautioned against treating the Hugging Face incident as justification for weakening the cybersecurity safeguards protecting advanced American systems.
“The answer is not simply to remove them,” Shrenik Kothari of Robert W. Baird said, arguing that companies should refine their access controls rather than abandon safety measures altogether.
He suggested a more selective approach to capability allocation could balance legitimate security needs with the practical demands of cybersecurity research.
Via Reuters

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Chinese Zhipu AI GLM-5.2 succeeded where leading American models failed woefully Hugging Face breach reignited Washington’s battle over open-weight artificial intelligence Safety guardrails unexpectedly complicated defensive cybersecurity work during a real incident The recent cybersecurity incident involving Hugging Face has unexpectedly placed a Chinese open source AI model at the…
Recent Posts
- A stratospheric balloon could become a high-altitude drone carrier, capable of loitering for weeks and launching solar-powered UAVs
- In a twist of irony, a Chinese open source GLM 5.2 AI model contained ‘rogue’ OpenAI GPT-5.6 Sol in a Hugging Face hack just as the US mulls banning open-weight AI
- Quordle hints and answers for Monday, August 3 (game #1652)
- Quote of the day by pioneer of cybernetics Norbert Wiener: ‘The automated machine is the economic equivalent of slave labour’ — foreshadowing the displacement of human labor in the years to come
- Rachika Nayar’s Heaven Come Crashing is an instrumental epic of desperate longing
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023