
23 April 2024 | Blog

Author: Zexian Li, Orange Cyberdefense China
After the incident attribution was made public, Hugging Face CEO Clément Delangue put forward two requests:
These two requests were made publicly on social media around July 26, 2026. More precisely, they should be described as a request for compute support for defensive research, rather than a “formal $100 million claim” that has already entered legal proceedings. (https://www.reddit.com/r/LocalLLaMA/comments/1v72jft/ceo_of_hugging_face_in_the_spirit_of_transparency/
Traditional incident reports typically include:
For autonomous agents, however, this information is still insufficient.
Researchers also need to understand:
Complete execution traces can help external researchers distinguish among three categories of problems:
Without the model and tool-call traces, and with only the final attack chain available, we can know what happened, but it is much harder to understand precisely why it happened.
The request is not merely a demand for resource compensation.
It points to a resource imbalance in frontier AI safety research:
If the risks of a frontier experiment can cross organizational boundaries, the cost of that experiment should not be calculated solely in terms of internal GPUs, researchers, and development time. It should also include the security costs that may ultimately be borne by external parties.

Any discussion of whether AI will replace security engineers must ultimately return to practical work. Security teams should not treat AI merely as a question-and-answer tool, nor should they give agents direct production privileges. A more reasonable approach is to place AI within a security workflow that is auditable, constrained, and capable of termination.
Agents can perform tasks such as:
Security personnel remain responsible for:
Agents can handle:
However, external constraints must be imposed:

AI is particularly well suited to processing large volumes of heterogeneous logs:
However, model outputs must be traceable to evidence.
A qualified forensic agent should not simply report: “The attacker may have accessed the database.”
It should provide the supporting evidence at the same time, preventing hallucinations from leading to incorrect conclusions:
Partial excerpt from an investigation report produced by an internal OCD China agent (one of several):


23 April 2024 | Blog

22 November 2023 | Blog

18 June 2024 | Blog