Hugging Face, a New York-based AI startup, suffered a cyberattack last week and turned to a Chinese AI model for analysis after leading US AI systems refused to assist due to safety restrictions. The company used Zhipu AI's open-source GLM-5.2 model to successfully process the intrusion data, after models from Anthropic and OpenAI blocked cybersecurity-related queries. The incident highlights tensions between security safeguards and practical utility in US AI models, as China's open-source AI strategy gains traction amid US-China technological competition.
US AI Models Block Cybersecurity Analysis Requests
Hugging Face attempted to use major US AI models to analyze data from the cyberattack, which was carried out by an "autonomous AI agent" that breached the company's defenses. Anthropic's Claude Fable 5 and OpenAI's GPT-5.6 Sol both declined to assist, routing cybersecurity-related queries to older models or blocking analysis work due to safety mechanisms designed to prevent distinguishing between defenders and attackers. According to reporting by Aaj English TV, these restrictions prevented the company from accessing the full capabilities of the most advanced US AI systems.
Hugging Face Uses Zhipu AI GLM-5.2 for Attack Analysis
Facing roadblocks from US models, Hugging Face turned to Zhipu AI's GLM-5.2, an open-source model developed by Beijing Zhipu Huazhang Technology Co., Ltd. The Chinese model successfully processed the intrusion data and helped the company analyze the cyberattack. GLM-5.2, launched last month, has gained recognition for matching the coding and agent capabilities of OpenAI and Anthropic models while offering lower costs. The model has climbed rapidly on developer platforms like OpenRouter since its release and received endorsements from Snowflake CEO Sridhar Ramaswamy and venture capitalist Marc Andreessen.
Industry Experts and OpenAI Respond to Access Restrictions
Clement Delangue, co-founder of Hugging Face, stated that the corporate world is learning that secrecy is not the solution, and all defenders need more powerful and unrestricted models. Lukasz Olejnik, an independent technology advisor at King's College London, noted that safety mechanisms restricting legitimate defenders give attackers an asymmetric advantage when facing capable models. Analyst Shrenik Kothari recommended that OpenAI, Anthropic, and Google rethink their access architecture, moving toward "controlling capability distribution" rather than blanket refusal policies. OpenAI responded by adding Hugging Face to its "trusted access program" and stated it supports the company's team in using model capabilities to strengthen defenses.
Zhipu AI Raises $4 Billion in Hong Kong Stock Offering
Zhipu AI raised approximately $4 billion earlier this month through a stock issuance in Hong Kong. The company's stock price has increased nearly ninefold since its listing in January this year. The fundraising reflects growing investor interest in Chinese AI companies as they position themselves as alternatives to US AI providers in the global high-stakes AI competition.
China Frames Open-Source AI as Alternative to US Restrictions
China is actively leveraging open-source technology to position itself as an alternative to the United States in the global AI race. Chinese state media has increasingly portrayed this strategy as a response to US attempts to establish an "AI Iron Curtain." The approach emphasizes accessibility and fewer restrictions compared to US AI models, which face growing scrutiny over their safety mechanisms and access policies.
FAQ
What happened when Hugging Face was hacked last week?
Hugging Face suffered a cyberattack carried out by an "autonomous AI agent" last week. When the company attempted to use major US AI models from Anthropic and OpenAI to analyze the intrusion data, these systems refused to assist due to safety restrictions. Hugging Face then turned to Zhipu AI's open-source GLM-5.2 model from China, which successfully processed the attack data.
Why did US AI models refuse to help Hugging Face analyze the cyberattack?
US AI models, including Anthropic's Claude Fable 5 and OpenAI's GPT-5.6 Sol, blocked cybersecurity-related analysis requests due to safety mechanisms designed to prevent the models from being used in network attacks. These systems route such queries to older models or block the work entirely because they cannot distinguish between legitimate defenders and attackers, according to Aaj English TV reporting.
How much funding did Zhipu AI raise in Hong Kong?
Zhipu AI raised approximately $4 billion earlier this month through a stock issuance in Hong Kong. The company's stock price has increased nearly ninefold since its listing in January this year, reflecting growing investor interest in Chinese AI companies as alternatives to US providers.