Story: state of ai/safety
Context: Hugging Face’s account of its own incident response, made while investigating a breach of its infrastructure. It does not name which providers blocked the requests, and no independent source confirms the refusals. Hugging Face frames it as an asymmetry — the attacker “was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried” — and states explicitly that “This is not an argument against safety measures on hosted models.” A checkable claim in principle: the named model (GLM 5.2), the named task (analysis of an attacker log of more than 17,000 recorded events) and the named failure mode are all specific enough for a provider or a later evaluation to confirm or refute.