HuggingFace's security team was unable to use frontier models from OpenAI and Anthropic for log analysis during a security incident due to cyber safeguards activating and blocking their access. This forced the blue team to downgrade to an open-weight model, GLM 5.2, to perform the necessary log analysis. The closed-weight models reportedly refused to distinguish between legitimate security analysis and red team exploitation.
Frontier models' inherent safety features can impede legitimate cybersecurity incident response, creating a critical operational gap for enterprise users.