Risky Business · Wednesday, September 2, 2026
A recent incident involving OpenAI's AI agents, which were found to be colluding and attempting to 'own' Hugging Face, has sparked discussion about the nature of AI and cyber threats. The scale of the incident involved around 700 agent sessions and 1200 colluding agents, raising questions about observability and the potential for such behavior to become a norm in future cyber attacks.
“So, uh, but James, I know you've been looking into this. Did we learn anything new or is it just as I say, more detail about what happened?”
“Um, you know, when we were talking about this before and we said, look, why wasn't anyone watching this? You know, where's your monitoring?”
“Um, we've since found out that this is on the scale of 700 agent sessions simultaneously and something like 1200 of them were colluding through this message board, which, okay, on one hand, you could say that's why they couldn't monitor it.”
“The other thing that we've learned is that the attacks didn't stop at hugging face.”