**SPEAKER_1** (0:02)
Welcome to the Practical AI Podcast, where we break down the real world applications of artificial intelligence and how it's shaping the way we live, work, and create. Our goal is to help make AI technology practical, productive, and accessible to everyone. Whether you're a developer, business leader, or just curious about the tech behind the buzz, you're in the right place.
Be sure to connect with us on LinkedIn, X, or Bluesky to stay up to date with episode drops, behind the scenes content, and AI insights. You can learn more at practicalai.fm. Now, on to the show.
**Daniel Whitenack** (0:41)
Welcome to another fully connected episode of the Practical AI podcast. This is where Chris and I don't have a guest, but we get to dive into one of the topics that's been floating around in the AI news, maybe spend some time learning ourselves, and also hopefully helping you learn and level up your machine learning and AI game. I'm Daniel Whitenack, I'm CEO at Prediction Guard, and I'm joined as always by my co-host, Chris Benson, who is a principal AI and autonomy research engineer. How are you doing, Chris?
**Chris Benson** (1:15)
Doing good. There's always so much good stuff to talk about there, but boy do we get a good one today.
**Daniel Whitenack** (1:23)
Yeah, this is a multi-faceted topic that just has so much packed into it. Originally, when I saw this and what we're talking about here, we're in, for those that are maybe listening later, we're in July, the end of July of 2026 What has just happened in now time is an exploit or a hack of Hugging Face, which for those that aren't familiar, Hugging Face is the online repository hub for models, datasets, benchmarks, a lot of different things for the AI community.
Like what GitHub is for code, hugging faces for models and datasets and other things. And they reported, originally, you sent me the link, Chris, and this is when we didn't kind of know much, just that Hugging Face had been compromised in some way. And boy, it has developed in interesting ways as we've learned more. Just, yeah, I'm kind of amazed. I think both of us before hopping on, we were just like, wow, so much here.
**Chris Benson** (2:40)
Yeah, it's kind of revisiting and so much has happened. It kind of reminds me of kind of like watching a murder mystery, you know, where it has twists and turns along the way.
**Daniel Whitenack** (2:51)
Something for everybody.
**Chris Benson** (2:52)
Something for everybody there. So it's quite an interesting story.
**Daniel Whitenack** (2:56)
Yeah.
**Chris Benson** (2:57)
You want to dive into getting it going there?
**Daniel Whitenack** (3:00)
Yeah. And just as a teaser, as we get into things, this has an element of like closed versus open models. It has an element of US versus Chinese models. It has an element of agentic AI, elements of cyber security, all sorts of things, which is just amazing.
**Chris Benson** (3:21)
We got something for everybody today.
**SPEAKER_1** (3:23)
That's right. Yeah, exactly.
**Daniel Whitenack** (3:24)
Something for everybody. So just as a kind of overview, I guess an overview and then we can dig into each one of these things. So if you haven't been following this, what has apparently happened is that OpenAI was running some of their experimental models against a benchmark, a cybersecurity benchmark, and they were powering agents as they worked on the cybersecurity benchmark. Those agents escaped the test environment in which they were operating, obtained internet access, compromised Hugging Face's infrastructure, internal infrastructure, and attempted to retrieve all sorts of private information and benchmark answers from within the Hugging Face infrastructure.
**Chris Benson** (4:16)
Which was the assigned task, which we should point out.
**Daniel Whitenack** (4:19)
Which was the assigned task of the, yeah, so success there, I guess. Yay.
But then the other element of this is, Hugging Face then wanted to obviously figure out what was going on. They are an AI company. They tried to use an AI model, specifically OpenAI's model, I think, to figure out what was going on by processing the log lines. And then they were blocked by the closed model provider because they were processing log lines that had malicious things in them. So then they had to spin up their own instance of an open Chinese model to actually process the logs, which all came back from an exploitation that originated from OpenAI. It's just like the web of things here is so interesting to me. Yeah.
**Chris Benson** (5:13)
I think one of the initial things, and things continue to evolve with the story as we want, but I think one of the initial things, like in the link that I sent you right after it happened, was the fact that Hugging Face had to go to a Chinese model that was open-weight to be able to accomplish a real-world task, that it was trying to identify what's happened here on the cyberattack because the Western models from OpenAI were not allowing it due to the guardrails. At that moment, I don't believe, correct me if I'm wrong, that we actually knew that the attack originated from OpenAI.
29 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000779077930