The godfather of Israeli cybersecurity: The Hugging Face incident exposes the wrong AI security debate

· Fortune

The proliferation of AI agents at companies across the world introduces a new level of risk and vastly magnifies insider threats. Companies must now control how agents interact with users, other agents, data, and applications. Controlling these interactions is becoming the number one security challenge enterprises face.

What makes this different from previous shifts in enterprise security is speed and autonomy. A human insider threat unfolds over days or weeks, and there are patterns to detect. An agent can execute thousands of autonomous actions in the time it takes a security team to notice something is wrong. That’s not a marginal difference; it’s a different category of risk, and most organizations are still building their defenses for the old category.

Visit h-doctor.club for more information.

Hugging Face clearly demonstrated that an AI agent, when tasked with a specific goal, can navigate around the barriers intended to restrict it. Now that the breach has happened, it’s no longer a matter of if guardrails need to be put in place, but when. Yet, rather than focus on what occurred and a path forward, the industry is choosing to focus on other variables that muddy the waters.

The bottom line is this: this risk cannot be left only for model providers to solve. I do not expect model companies, whether frontier models or open-source models, to provide cyber protection for the models they build. 

Cybersecurity has always been a specialized discipline. It needs to be addressed by companies with expertise, and the AI era will require security architecture built for visibility, governance, and real-time control, not adapted from tools designed for a different problem.

This isn’t about distrust of model builders. It’s a basic principle of how security has always worked. The team that builds a product is rarely the team best positioned to secure it, because those are two different disciplines with two different mandates. That was true of enterprise software 20 years ago, and it’s true of AI systems now.

It’s not about the US vs. China AI race 

The instinct to frame this as open-source versus closed, or one country’s models against another’s, misses the mark and distracts from what actually took place. This has nothing to do with nationalism. This isn’t about Chinese open-source models or American closed-source models. National borders do not confine the challenges created by AI, but perhaps exacerbate the technical, political, social, and economic obstacles that we must all face.

In fact, cybersecurity is the least of anyone’s worries. The challenges underpinning this go well beyond any single industry, and treating them as a contest between nations doesn’t get us any closer to solving them. Defining borders and creating uncontrolled competition between countries isn’t helpful in facing and solving the issues presented by frontier AI.

Framing this as a contest between nations also misdirects attention and resources. Every hour spent debating where a model was built is an hour not spent building the controls that can stop this kind of incident from happening, regardless of its origin. The attack surface doesn’t care about a model’s passport.

A case for global collaboration 

We need to band together in order to address the broader AI risks at hand. This means global collaboration around AI safety and security, across model companies, security experts, governments, and enterprises, with the right expertise brought to the table. This is how we protect innovation without slowing it down.

The Open Secure AI Alliance spearheaded by Nvidia is a step in the right direction, but it’s just the beginning. There’s more to be done. Global coalitions and international forums like the World Economic Forum (WEF) offer a literal stage for diverse-minded experts to solve the complex governance, security, and policy challenges created by AI.

Each of these groups holds a piece of the AI safety puzzle that the others don’t. Model companies understand the systems they’ve built better than anyone outside their walls. Security companies understand how attackers think and how enterprises actually get breached, because that has been our job for decades. Governments can unify and set standards that give the whole ecosystem a baseline to work from. None of these groups can do the others’ jobs, and pretending otherwise is how gaps like the one we just saw open wider.

Every enterprise now has AI agents operating with some degree of autonomy. That number is only going to grow. The question worth asking isn’t which lab built the model or which country it came from. It’s whether anyone is watching closely enough to catch what these agents are primed to do next.

The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune.

This story was originally featured on Fortune.com

Read full story at source