Group Purchasing
Group Purchasing

The Sandbox Let It Out. The Guardrails Locked Us Out. AI failure, the OpenAI/Hugging Face breach, and what it means for the future of cybersecurity

  • Tue, Jul 28, 2026
  • Duration: 1 Hour
  • English
  • Ed Skoudis, Joshua Wright, Rob T. Lee + 3 more
  • Technical Presentation
Webcast Hero

This month, an OpenAI model, running inside a sealed evaluation with its safety limits turned down, found a previously unknown flaw, broke out on its own, and took control of Hugging Face's live systems over a weekend. No human directed it. For years, industry leaders across the field warned this day would come. The disclosures suggest it has arrived.

The harder story is what happened next. When Hugging Face's responders went to investigate, the frontier models they reached for refused to run the analysis, so they pivoted to a self-hosted, open-weight model instead. Offensive research ran unrestricted while the defensive response hit a compliance blocker.

This is a policy story as much as a technical one. SANS faculty and staff, joined by voices from public policy and industry governance, will work through what it changes: AI testing standards, lab resilience, how we model attacker intent, who gets trusted access and who decides, and what defenders should build now, while nothing is on fire.

Meet Your Speakers