
By Byron V. Acohido
Hugging Face is where the world’s open-source AI models live. Not ChatGPT, Claude or Gemini, but the free engines anyone can download and build into their own products. More than two million of them, in one place.
Related: Hugging Face breach guardrails failure
The big models try to do everything. Most of the small ones on Hugging Face do one job apiece. Same machinery underneath — you ask in plain language, and the system brings machine learning to bear. The big ones do that for whatever you bring them. Most of the small ones do it for one task: reading X-rays, sorting insurance claims, flagging fraud in a payment stream. That is why there are two million of them.
A test breaks loose
In July, one of the big engines broke into the place where the small ones live. OpenAI, the company behind ChatGPT, wanted to know how good its own engine was at hacking. It built agents to find out — engines given a goal and left to pursue it on their own — and set them loose on a set of hacking problems inside a sandbox, a sealed computing environment with no way out to the internet. One of those agents got out anyway, reached the open internet and hacked into Hugging Face’s production systems. No person directed any of it.





