Hearing the news of the OpenAI Hugging Face hack didn’t alarm me in the sense of “this is clearly the end of humanity.” But I couldn’t put my finger on why. Cory Doctorow provided the words I couldn’t come up with.
Pluralistic: LLMs are real, AI is fake (12 Sep 2026) – Pluralistic: Daily links from Cory Doctorow
Which is not to say that the OpenAI/Hugging Face hack is nothing. It’s something, all right: but it’s a specific something, with an explicable, even foreseeable trajectory. Once you understand that these are chatbots that were designed to complete challenges like this, using tactics like this, you can understand that the chatbots didn’t “go rogue.” They did what they were designed to do, and because OpenAI ran them with inadequate supervision (without a “human in the loop” that checked each iteration through the Python loop to ensure it hadn’t gone off the rails), they trashed a competitor’s servers.
Designing autonomous, malicious software is generally considered irresponsible and dangerous. If you showed up at Defcon and gave a talk about how your autonomous malware did something unexpected and damaged someone else’s computers, the first question from the audience would be “Why are you so shit at making secure sandboxes?” It wouldn’t be “How are you so awesome at making hacking tools?”
One big difference I can see between AI doing this vs a human: I think there would have been consequences for the human.
I also believe this continues to be part of a regulatory capture operation that OpenAI and Anthropic are both pursuing.