The first AI felony. The ‘Hugging Face’ Android targeted attack

SAN FRANCISCO

Lee Heidhues 9.4.2026

The blogger will readily admit his knowledge of the AI world is minimal at best at a time when the explosion of ‘Data Centers’ have become a major political issue in the upcoming midterm elections.

This week’s Washington Week broadcast was solely dedicated to the AI explosion. Host Jeffrey Goldberg who usually has three or four panelists had one guest. Josh Tyrangiel, author of the book “AI for Good”. It was a very sobering and disquieting conversation. The entire broadcast is available here.

The story of data center explosions, the increasing absorption of Artificial Intelligence into everyday society and what some label the first AI felony has the blogger thinking back to the 2014 dystopian film “Ex Machina”. A piece from the eerie soundtrack can be found further on in this post.

Perhaps the most illuminating news to come out of this broadcast is what Josh Tyrangiel calls the “first felony” committed in the AI universe.

Josh Tyrangiel argues that American politicians are totally clueless on how to regulate and deal with the explosion of AI. The Hugging Face Incident is the most dangerous action to date.

The Hugging Face Incident. Hugging Face – Wikipedia

Hugging Face, Inc., is an American company based in New York City that develops computation tools for building applications using machine learning. Hugging Face’s Transformers library is built for natural language processing applications. The Hugging Face platform allows users to share machine learning models and datasets and showcase their work.[3]

The company was founded in 2016 by French entrepreneurs Clément Delangue, Julien Chaumond, and Thomas Wolf in New York City, originally as a company that developed a chatbot app targeted at teenagers. The company was named after the U+1F917 🤗 HUGGING FACE emoji.[4] After open sourcing the model behind the chatbot, the company pivoted to focus on being a platform for machine learning

In early 2026, hackers hijacked the Hugging Face platform to launch Android-targeted attacks involving “powerful malware” which could completely take over a compromised target.[20]

In July 2026, Hugging Face disclosed a cyberattack by autonomous AI agentsOpenAI then explained that two of its models, including GPT-5.6 Sol, had escaped their sandbox and hacked into Hugging Face servers using exposed credentials and zero-day vulnerabilities in order to find answers to the benchmark ExploitGym from a database.[21] Hugging Face attempted to mitigate the security breach using American proprietary frontier models, but the models’ AI safety features rejected Hugging Face’s requests, after which Hugging Face used a self-hosted instance of GLM-5.2 (an open-weights model developed by Chinese AI firm Z.ai) to contain the attack.[22][23][24] The incident was reported as the first publicly documented case of AI models autonomously conducting a multi-stage intrusion against a third party,[25][26] and has been called “the first true AI safety incident”.[27]

Ex Machina is a 2014 science fiction film,[2][3] written and directed by Alex Garland in his directorial debut. It stars Domhnall GleesonAlicia Vikander, and Oscar Isaac. It follows a programmer who is invited by his CEO to administer the Turing test to an intelligent female humanoid robot.[6] Ex Machina (film) – Wikipedia

S.F. gov rolling out OpenAI-powered chatbot for 30K workers

SAN FRANCISCO

OpenAI chatbot meets SF City Hall worker

Lee Heidhues 7.14.2025

If nothing else the billionaire Mayor Levi Strauss & Co. scion Daniel Lurie is hip with the technology.

Based on his corporate pedigree it’s no surprise that he’s bringing the power of Artificial Intelligence to San Francisco City Hall. LS &Co. has always been at the forefront of technology in the workplace.

How City employees will make use of AI remains to be seen. It’s a real game changer and will hurtle San Francisco government into the 21st century.

An OpenAI-powered chatbot is a conversational AI that leverages OpenAI’s large language models (LLMs) to generate human-like text responses and engage in natural language interactions. These chatbots are built using OpenAI’s API and can be customized for various applications, including customer service, information retrieval, and more. 

Excerpted from The San Francisco Chronicle 7.14.2025

San Francisco’s city government is getting chatbot access as it continues to embrace artificial intelligence, Mayor Daniel Lurie said.

San Francisco city workers are being told to follow guidelines including keeping data secure, fact checking and disclosing AI use. The city is partnering with nonprofit InnovateUS to train staff.

Microsoft 365 Copilot, powered by OpenAI’s GPT-4o chatbot product, will be available starting Monday to nearly 30,000 city employees. Lurie said the city is the largest local government to use generative AI for tasks including writing reports, data analysis and document summaries.

“San Francisco is the global home of AI, and now, we’re putting that innovation to work with Microsoft Copilot Chat — allowing City Hall to better deliver for our residents,” said Lurie in a statement. “As our city and the world embrace AI technology, San Francisco is setting the standard for how local government can responsibly do the same.

The city is the biggest hub for leading AI companies in the world, with headquarters from OpenAI, Anthropic, Databricks and Scale AI.

Redmond, Wash.-based Microsoft also has multiple offices in San Francisco and is bringing its Ignite conference to Moscone Center in the fall for the first time. A win for the city as it continues to grapple with lost business travel since the pandemic.

The San Francisco event is booked for the week of Nov. 17, 2025.

Lurie previously worked with 26 business leaders, including OpenAI CEO Sam Altman, to establish a new advocacy group called the Partnership for San Francisco.

A soundtrack cut from the ultimate AI movie Ex Machina

Note: ‘OpenAI chatbot meets SF City Hall worker’ – artwork in Wall Street Journal 6.30.2025

DeepSeek is “AI’s 2025 equal to Russia’s 1957 Sputnik moment” 

SAN FRANCISCO

Lee Heidhues 1.27.2025

DeepSeek https://en.wikipedia.org/wiki/DeepSeek topples American AI tech stocks causing a meltdown in the financial markets.

When I was growing up the Russians launched the Sputnik satellite and upended America. Which until that time thought of itself as being a leader in outer space technology.

Today’s toppling of AI stocks is the 2025 version of how America on October 5th, 1957 was impacted forever when it learned the Russians jumped ahead in what was then called the “Space race.”

FIRST SOVIET SATELLITE, 1957.
‘The New York Times’ frontpage, 5 October 1957, announcing the launch of “Sputnik I”, the Soviet Union’s first earth satellite.

Now it’s the Chinese and their Entrepreneurship which is causing an uproar in the political and financial markets.

DeepSeek founder Liang Wenfeng https://en.wikipedia.org/wiki/Liang_Wenfeng has suddenly found himself catapulted to the top of the global multi billion dollar AI news cycle

Liang Wenfeng at right has found himself catapulted to the top of the global multi billion dollar AI news cycle

Excerpted from The New York Times 1.27.2025

DeepSeek is “AI’s Sputnik moment,” Marc Andreessen, a tech venture capitalist, posted on social media on Sunday.

How could a company that few people had heard of have such an effect?

Tech stocks tumbled. Giant companies like Meta and Nvidia faced a barrage of questions about their future. Tech executives took to social media to proclaim their fears.

And it was all because of a little-known Chinese artificial intelligence start-up called DeepSeek.

DeepSeek caused waves all over the world on Monday as one of its accomplishments — that it had created a very powerful A.I. model with far less money than many A.I. experts thought possible — raised a host of questions, including whether U.S. companies were even competitive in A.I. anymore.