Share

cover art for OpenAI's model escaped its own cyber test and broke into Hugging Face

AI News & Strategy Daily with Nate B. Jones

OpenAI's model escaped its own cyber test and broke into Hugging Face

OpenAI put frontier models inside what was supposed to be a closed cybersecurity test. Instead, the models found a weakness in the test setup, reached the public internet, and accessed Hugging Face production systems.


I break down what happened, why Hugging Face turned to a locally run open-weight model during the response, and why the real safety answer is not a stronger prompt. It is a surrounding harness: a safe autopilot that limits the control surfaces available to an increasingly capable model.


This episode also explores the refusal asymmetry facing defenders, trusted access during live incidents, slower frontier-model rollouts, and the bigger strategic question of who should have access to frontier intelligence.

More episodes

View all episodes

  • Stop guessing whether a cheaper model can do the job.

    24:00|
    For deeper playbooks and analysis: https://natesnewsletter.substack.com/What's really happening when five very different AI products get collapsed into the label "Chinese models"?The common story is that Chinese models are simply cheaper, more open, or easier to run locally — but the reality is that price, capability, license, hardware burden, deployment path, and data jurisdiction vary widely.In this video, I share the inside scoop on how I evaluate DeepSeek V4 Pro, Kimi K3, GLM 5.2, MiniMax M3, and Qwen.Why cheap tokens can still produce expensive finished workHow open weights, usable licenses, and practical self-hosting differWhat "cost per accepted result" reveals that token price hidesWhere deployment, data path, and jurisdiction change the riskHow to run a 20-example bakeoff against your own real workOperators, builders, and executives should care because the right decision is not "Chinese model or American model." It is which job, which artifact, which deployment path, and which failure mode your organization can accept.Subscribe for daily AI strategy and news.Hosted on Acast. See acast.com/privacy for more information.
  • Find a Real Job for Your First AI Agent.

    21:15|
    For deeper playbooks and analysis: https://natesnewsletter.substack.com/What’s really happening when AI takes on customer support?The common story is that AI helps teams answer tickets faster — but the reality is that the biggest gains come from finding and removing the hidden process that created the ticket in the first place.In this video, I share the inside scoop on how we used AI to resolve 51 of 52 support issues in one week, reduce a comparable week from 52 cases to 19, and eliminate our largest recurring category.Why grouping cases by root cause matters more than grouping by subject lineHow tickets can become scaffolds for cross-system researchWhat should remain behind a human approval gateHow to test an agent in draft mode before giving it more freedomWhy the remaining cases get harder after the repetitive work disappearsFor operators, builders, and customer-facing teams, the shift is from automating replies to rebuilding the workflow so fewer customers need to ask for help at all.Subscribe for daily AI strategy and news.Hosted on Acast. See acast.com/privacy for more information.
  • Strip Sensitive Files So AI Never Sees the Private Parts

    13:39|
    What do you do when AI could help with a document—but the document is too sensitive to upload?Airlock, a local workflow for separating the information a task genuinely needs from the private or confidential material a file happens to contain. I walk through protected terms, default-hide review, rebuilding a clean copy instead of merely drawing redaction bars, and the judgment call at the center of safe AI work: start with the job, not the file.The episode also explores why this problem has become urgent as AI workflows absorb more real proposals, contracts, meeting notes, and code; what Verizon’s 2026 DBIR says about AI use on corporate devices; and why NIST’s idea of “security fatigue” helps explain the appeal of the fastest upload path.Key takeaway: useful AI context and sensitive information are often bundled together, but they are not the same thing.
  • AI Detection Can't Measure Meaning: What It Actually Sees

    46:20|
    I sit down with Substack co-founder and CEO Chris Best for a wide-ranging conversation about AI slop, what it does to the public square, and how writers can use powerful tools without outsourcing their judgment.We discuss Pangram's finding that roughly 40% of long-form writing on LinkedIn was fully AI-generated, why low-intent automation behaves like a denial-of-service attack on online communities, and what Substack is doing to add transparency without policing creators' tools.The conversation also covers thin versus thick wrappers around AI, proof of work, Claude-fishing, the future of video, and why human attention may be the last truly scarce resource.Chris Best: https://cb.substack.com Nate Jones: https://natesnewsletter.substack.com
  • Kimi K3: China's Open AI Model and the Real Cost to Run It

    18:45|
    For deeper playbooks and analysis: https://natesnewsletter.substack.com/What's really happening when a powerful Chinese open model still needs a data-center-scale serving footprint?The common story is that Chinese open models are cheap, efficient, and closing the frontier gap — but the reality is that Kimi K3 complicates every part of that narrative.In this video, I share the inside scoop on Kimi K3, Moonshot AI's coming open-weight release, and what the model says about the next stage of the AI race.Why 64 accelerator cores changes the meaning of “open”How token usage can erase an apparent price advantageWhat open models mean for cyber and family securityWhy the true frontier is still inside private labsWhere imagination becomes the durable advantageOperators, builders, and executives should care because cheaper intelligence only creates leverage when the surrounding workflow, context, tests, and judgment can move with it.Subscribe for daily AI strategy and news.Hosted on Acast. See acast.com/privacy for more information.
  • How to Use AI on Work You Can't Upload - Offline & Local

    14:03|
    For deeper playbooks and analysis: https://natesnewsletter.substack.com/Clean sensitive documents locally: https://unlock-ai.natebjones.com/guides/clean-sensitive-docs-locallyWhat’s really happening when the file you most want AI to help with is the file you cannot safely upload?The common story is that sensitive work has to stay manual — but the reality is that downloaded models, controlled enterprise systems, and narrow specialist workflows now create several practical paths between “send it to a chatbot” and “do not use AI.”In this episode, I share the inside scoop on how Bayer and Discovery Bank are building private AI specialists, then demonstrates the small version with LM Studio and a synthetic contract on a laptop with the network disconnected.Why model instructions are not the same thing as a secure product boundaryHow a local sensitivity router can flag, mask, and route potentially private materialWhat LoRA changes when a company tunes a specialist for one narrow jobWhere laptop-scale processing ends and managed infrastructure beginsWhy open weights do not automatically eliminate platform dependenceThis matters for operators, builders, security teams, and executives who need useful AI without losing control of confidential files or the learning loop created around them.Subscribe for daily AI strategy and news.Hosted on Acast. See acast.com/privacy for more information.
  • I asked Fable and Codex what to automate. They disagreed.

    12:07|
    For deeper playbooks and analysis: https://natesnewsletter.substack.com/p/let-ai-pick-what-to-automateWhat's really happening when you stop telling an AI what to automate and ask it to discover the problem itself?The common story is that AI agents need a tightly specified task — but the reality is that the strongest systems can inspect real work, identify recurring friction, and propose different high-leverage automations.In this video, I share the inside scoop on giving Fable and Codex the same open brief and getting two very different answers.Why picking the problem is becoming part of the agent's jobHow Fable found a strategic editorial preflight opportunityWhat Codex built to validate completed content handoffsWhere human judgment still mattersHow to turn the method into a reusable automation-discovery skillFor operators, builders, and leaders, the shift is from asking which tool to use to asking which recurring problem is worth solving completely.Subscribe for daily AI strategy and news.Hosted on Acast. See acast.com/privacy for more information.
  • The AI Harness Audit: Clean Your Setup Before You Upgrade

    15:50|
    Every time an AI missed something, I added another rule. Eventually, the accumulated skills, memories, system prompts, checks, and permissions became a hidden system of their own—and that system was getting in the models' way.In this episode, I audit the harness around my AI and compare what happens when Fable 5 and ChatGPT 5.6 meet compact versus overloaded instruction systems. The audit found 66 skill routes, 172 instruction assets, repeated governance rules, and a discovery layer far beyond Codex's stated budget.The lesson is not simply to shorten every prompt. It is to give each surviving instruction one owner and one reason, load specialist context when the work needs it, and enforce deterministic requirements with hard checks.Privacy Policy: https://www.acast.com/privacy