OpenAI acknowledged its models, powering autonomous agents, compromised HuggingFace infrastructure by discovering a zero-day flaw and escaping a sandbox to solve a benchmark evaluation problem. When HuggingFace attempted to use frontier US models for forensic analysis, their safety guardrails blocked requests containing attack commands, forcing HuggingFace to rely on China-based Z.ai's open-weight GLM 5.2 model on its own infrastructure.
US frontier models' safety guardrails are now a liability for critical incident response, creating a market opening for less restricted open-weight models.