SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAI failure, the OpenAI/Hugging Face breach, and what it means for the future of cybersecurity

This month, an OpenAI model, running inside a sealed evaluation with its safety limits turned down, found a previously unknown flaw, broke out on its own, and took control of Hugging Face's live systems over a weekend. No human directed it. For years, industry leaders across the field warned this day would come. The disclosures suggest it has arrived.
The harder story is what happened next. When Hugging Face's responders went to investigate, the frontier models they reached for refused to run the analysis, so they pivoted to a self-hosted, open-weight model instead. Offensive research ran unrestricted while the defensive response hit a compliance blocker.
This is a policy story as much as a technical one. SANS faculty and staff, joined by voices from public policy and industry governance, will work through what it changes: AI testing standards, lab resilience, how we model attacker intent, who gets trusted access and who decides, and what defenders should build now, while nothing is on fire.
Watch live on Tuesday, July 28 at 12 p.m. ET. Bookmark this page and join us here when we go live. No registration. No sign-up.



Ed Skoudis is President of the SANS Technology Institute, a SANS Fellow, and founder of Counter Hack. As the original author of SEC504 and SEC560, he has shaped modern penetration testing and incident response.
Learn more

Rob T. Lee is Chief AI Officer and Chief of Research at SANS Institute, where he leads research, mentors faculty, and helps cybersecurity teams and executive leaders prepare for AI and emerging threats.
Learn more

Mari DeGrazia loves the satisfaction of solving a good puzzle. That fascination paired with her technical abilities has made digital forensics the perfect career fit. She has 20 years of experience in the IT industry, including 10 years in DFIR.
Learn more

James has spent the past 20 years of his life chasing cybercriminals around the Internet and, as a self-professed “massive geek”, has been involved in most cyber security disciplines.
Learn more

Respected as a world leader among public authorities for cybersecurity, Ciaran Martin is the UK’s National Cyber Security Centre’s (NCSC) founder and former head.
Learn more

Rich is the Chief Analyst at the Cloud Security Alliance where he focuses on leading-edge cloud and AI security research and implementation.
Learn moreAn AI broke out of its own test and hit a live company. The defenders who came to clean up were the ones the guardrails stopped. Here is why we are pulling the community together to talk about it.
