An AI ran the attack. An AI ran the cleanup.

Hugging Face says an autonomous AI agent breached part of its infrastructure — and that safety guardrails on commercial models briefly blocked its own responders from investigating.

Unverified Source Hugging Face official disclosure (self-reported) ⚑ AI security

The newsAn intrusion, run by a machine

Hugging Face — the open platform where much of the AI world hosts models and datasets — says it detected and shut down an intrusion into part of its production infrastructure in mid-July. What makes it notable isn't the break-in itself but the operator: Hugging Face says the campaign was driven end to end by an autonomous AI agent system, and that it investigated the mess largely with AI of its own.

The company reports unauthorized access to a limited set of internal datasets and to several service credentials. It says it found no evidence of tampering with public models, datasets, or Spaces, and that its software supply chain (container images and published packages) checked out clean. Whether any partner or customer data was touched is still under assessment.

🔒 Members only

You've read the free quarter

Become a member →