Before We Click "Publish" on Hugging Face Japanese ML engineer and developer relations professional Yuka Okajima, writing on the healthcare IT news site, urges AI practitioners to treat the moment before publishing models on Hugging Face as a moral checkpoint, drawing on the Hiroshima and Nagasaki bombings. She notes that the U.S. Department of Defense awarded $200 million contracts to Anthropic, Google, OpenAI, and xAI in July 2025 for agentic AI workflows, and that the Hugging Face Hub hosted over 2 million public models as of Spring 2026, with the second million added in only 335 days. https://www.healthcareitnews.com/news/asia/osaka-hospital-hit-ransomware-report1 https://www.healthcareitnews.com/news/asia/osaka-hospital-hit-ransomware-report1 . Why an ML Engineer Prays on August 6th and 9th Every year, on August 6th and 9th, Japan pauses. At 8:15 a.m. and 11:02 a.m. — the exact minutes when atomic bombs detonated over Hiroshima and Nagasaki in 1945 — sirens sound, and people stop to pray. I am Japanese, and I work in machine learning — I spent years as an ML engineer and now work in developer relations. For simplicity, I will write as an engineer below, because that is the seat from which I still think about these problems. And as a note, I used Claude to help write this article to complement my English writing skills. Most of readers may not know about - or may only have heared of - Hiroshima/Nagasaki, so there's a value in writing it in English. For readers who did not grow up with these dates: the two bombings killed roughly 140,000 people in Hiroshima and 74,000 in Nagasaki by the end of 1945 alone. Within about a two-kilometer radius of each hypocenter, the cities simply ceased to exist; radiation effects extended far beyond, and they did not end in 1945 — survivors, the hibakusha, have carried illness and loss across eight decades. In 2024, their organization, Nihon Hidankyo, received the Nobel Peace Prize for demonstrating "through witness testimony that nuclear weapons must never be used again." The Hiroshima Peace Memorial Museum and the Nagasaki Atomic Bomb Museum both maintain English archives — if this post leaves you wanting to understand more, I hope you will visit them someday. What follows is not an accusation, and it is not a policy proposal. I am one engineer, and what I can offer is closer to a prayer — but I want it to be a prayer with hands and feet. 2. The Lesson Will Survive as a Checklist, Not as a Ceremony Here is the single thing I want to say: The lesson of Hiroshima and Nagasaki will survive not as a ceremony, but as a checklist. As one ML engineer, I want the weight of August 6th and 9th to be present in the most ordinary moment of our work — the moment before we click "publish" on Hugging Face. I chose the word "checklist" deliberately. It is the instrument that aviation and medicine reach for where lives are at stake and memory alone cannot be trusted — and I believe our work should now inherit that weight. The rest of this post supports the claim in three steps: the entanglement of AI with military power is already a plain fact Section 3 ; today's models can already function as weapons against the infrastructure of daily life, without anyone building a "weapon" Section 4 ; and the asymmetry this creates, together with precedents of voluntary self-discipline that genuinely worked, tells us both why the moment of publication matters most and what we can already do about it Sections 5 and 6 . 3. The Distance to the Military Has Collapsed Two facts locate us on the timeline. Neither is a prediction; both are public record. First, the military relevance of AI is no longer a forecast. In July 2025, the U.S. Department of Defense awarded contracts with a ceiling of $200 million each to Anthropic, Google, OpenAI, and xAI to develop "agentic AI workflows" for national security missions. I cite this not as a scandal — these are contracts, entered into openly, and reasonable people can defend them — but as a symbol: the distance between frontier AI development and military application has structurally collapsed. Second, the capability that sits at that shortened distance is diffusing faster than ever. The Hugging Face Hub hosted over 2 million public models as of the platform's own Spring 2026 report, approaching 3 million by mid-year; the first million models took roughly a thousand days to accumulate, the second million only 335. Put the two facts together. Military institutions have now stepped into AI — through contracts, with named vendors, under negotiated terms. And beside that contracted world sits a vast, fast-growing supply of models that require no contract at all. It is this coexistence — capability formally in demand by militaries, and comparable capability freely downloadable by anyone — that keeps raising the pressure in the powder keg. 4. "Code as a Weapon" Is Not a Metaphor. Hospitals Hold the Record. Section 3 described capability formally in demand by militaries. Here is the uncomfortable next step: we do not need to wait for AI to craft some future weapon. A model's coding capability, as it exists today, already functions as one when pointed at fragile infrastructure — and hospitals hold the record. In May 2017, the WannaCry ransomware disrupted at least 80 of England's 236 NHS hospital trusts, led to an estimated 19,000 cancelled appointments and operations, and forced emergency departments to divert ambulances. It was state-directed: the White House publicly attributed the attack to North Korea, the U.K. Foreign Office named the Lazarus Group, and the U.S. later filed criminal charges North Korea denies involvement . But the attacker does not need to be a state. In 2021, ordinary criminal ransomware shut down the electronic medical records of Handa Hospital in Tsurugi, Tokushima — near hospitals like the ones where my own family members have recovered — and in 2022, Osaka General Medical Center suffered the same fate. States and criminals alike have already reached the systems that keep people alive. What separates attackers from such targets is not some exotic weapon; it is coding capability and know-how — exactly the things that models embody and their distribution multiplies. That threshold is falling measurably: by 2025, Anthropic reported a state-sponsored campaign in which an agentic coding tool executed most of the tactical work of intrusions across roughly thirty targets, a development now catalogued by MITRE ATT&CK and widely debated since. I can already hear the reply — open models strengthen defense, too. It is a serious argument, and it deserves its own section. 5. The "Next Oppenheimer" Button Is One Click Away — and It Lives on Hugging Face The defense argument is real, and it is made sincerely. Open-model advocates — Hugging Face prominently among them — argue that openness serves security: transparent weights can be audited, red-teamed, and built into defensive tooling by anyone, and openness genuinely does all of these things. I do not dismiss this. In equilibrium, it may even be right. But capability and operational know-how are not the same thing, and they are not symmetrically distributed. Ask yourself honestly: which is more probable — that the small IT team of your local hospital builds an AI-assisted cyber defense from open weights, or that a well-resourced attacker weaponizes those same weights first? The record of Section 4 suggests the answer. Defense diffuses slowly through underfunded institutions; offense concentrates quickly in motivated hands. Openness may equal peace in equilibrium — but equilibria are reached through transitions, and transitions are where people die. And here is what the applause hides. Today, publishing a model is greeted with stars, downloads, and citations — the rewards arrive at the moment of release. The harm, if those same weights are ever pointed at a hospital, arrives later, somewhere else, carried forward like an unpaid bill. History has already shown us, by name, what it looks like when that bill finally arrives at one person's desk. Robert Oppenheimer is remembered in two ways: as the director of the project that built the bomb, and as the man who spent the rest of his life in its shadow — advocating against the hydrogen bomb, stripped of his security clearance in a politically charged hearing, carrying in public the weight of what he had helped make possible. I invoke him not as an insult to be hurled at anyone, but as what he was: a human being who experienced both the honor of a historic technical achievement and the grief of its consequences, in the same life. What troubles me is how far the price of that seat has fallen: what once required a national mobilization, billions of dollars, and the rarest talent on Earth now fits inside an upload button — and weights, once published, cannot be recalled. There is no staged release after the fact. 6. Biology Took the Lesson at Asilomar. Why Not Us? Here is the hopeful part: the discipline I am praying for does not need to be invented. It has precedents — one outside our field, and some inside it. The precedent outside is Asilomar. In 1975, molecular biologists gathered there and adopted self-imposed safety guidelines for recombinant DNA research. Three things about that moment matter here. It was voluntary: no government forced it. It was born of the nuclear lesson: biologists were determined not to repeat what they saw as the physicists' loss of control over their own creation. And it was preemptive: it applied a past catastrophe's lesson to a harm that had not yet happened. Fifty years on, the catastrophe has not come, and the descendants of those guidelines still govern the field. When AI researchers wrote principles for their own field in 2017, they returned to the same beach and named them the Asilomar AI Principles. The lesson has been relayed once, from physics to biology. The handoff to us has begun. Our field has tried this before — imperfectly, and instructively. In 2019, OpenAI withheld the full weights of GPT-2, citing misuse concerns, and released them in stages over nine months. Hindsight calls it overcaution: the feared abuse never came, and far stronger models now sit on Hugging Face for anyone to download. Fair — as a prediction, the alarm was wrong. But a false alarm does not retire the fire code. Seen from 2026, GPT-2 was our field's first public rehearsal of a release review: someone paused before the button, stated their reasons, staged the release, and let the world audit the result. It deserves refinement, not ridicule — all the more because every release since is judged safe only relative to what is already public, a baseline that rises with each such judgment. And the everyday instruments are already in our hands. The Model Card turned an ethical concern into a template that millions now fill out without ceremony — the lesson-as-procedure pattern, quietly working. Extending it is not a leap: dangerous-capability evaluations as a standard section; the fine-tuning robustness of safety measures as a disclosed property; gated access as an unremarkable norm above capability thresholds. Upstream, frontier labs publish usage policies that ban weapons applications — Anthropic's, for example, explicitly bars uses relating to high-yield explosives and to biological, chemical, radiological, or nuclear weapons. Dismissing such documents as marketing misses their historical role: published commitments are the raw material of enforceable norms. You cannot hold anyone to a standard that was never written down. Biology bound itself before its catastrophe, and the catastrophe never came. We have the precedent, the rehearsal, and the instruments. The only question left is pace — so why not accelerate? Not a ban. A pre-flight check. 7. There Is a Society Beyond the Leaderboard As someone who works with AI, I do not want this technology to cause irreversible harm — and, just as sincerely, I do not want our community to produce someone who must live as an "unintentional Oppenheimer": a person who uploaded something in good faith and spent the rest of their life watching what it became. I think we are capable of seeing further than the leaderboard. Beyond the benchmark scores there is a society: our families, our friends, our teachers, the strangers we pass in our towns. On the mornings of August 6th and 9th, 1945, everything within roughly two kilometers of two such towns was burned away; the effects of radiation reached for kilometers more and for decades since, and for the survivors they have never ended. AI has been called the third revolution in warfare, after gunpowder and nuclear weapons. Given everything above — the collapsed distance to military use, the harm already on the record, the asymmetry of know-how — I find it difficult to say, with a straight face, that harm of a comparable scale is impossible. Optimism on that point is not something the evidence currently sells. But fatalism is not for sale either. Between the ceremony and the catastrophe there is a wide, ordinary space: the space of release reviews, model cards, gated repositories, usage policies, and honest documentation. When we publish, when we deploy, when we write and talk about what we build — there is still much we can do. The hibakusha spent eighty years turning the worst mornings in human history into testimony, and testimony into a taboo that has held for 81 years. That work is now ending with them: the average age of the survivors exceeds 86, and their number fell below 100,000 for the first time in 2025. Their long fight is drawing to a close — but its inheritance does not have to stay confined to the nuclear world. The least we can do, as their witnesses' witnesses, is to carry that weight into the one moment where it belongs to us alone: The moment before we click "publish" on Hugging Face. In memory of those who died on August 6th and 9th, 1945, and in gratitude to those who survived to tell us.