{"slug": "hugging-face-uses-open-weights-z-ai-glm-5-2-to-defend-against-attacker-after", "title": "Hugging Face uses open weights Z.ai GLM 5.2 to defend against attacker after commercial frontier model refusal", "summary": "Hugging Face Inc. was forced to use Z.ai Co. Ltd.'s open-weights GLM 5.2 model to defend against an agentic AI attack after commercial frontier models from Anthropic and OpenAI blocked requests due to safety guardrails. The 753-billion-parameter GLM 5.2, which rivals Anthropic's Fable 5, enabled analysis within Hugging Face's firewall without data exposure. The incident highlights growing tension between Chinese open-source models and American closed-source models, as the U.S. government has restricted access to frontier models like Fable 5 and GPT 5.6.", "body_md": "### Hugging Face uses open weights Z.ai GLM 5.2 to defend against attacker after commercial frontier model refusal\n\nHugging Face Inc., an open-source artificial intelligence platform often described as the “GitHub of machine learning,” found itself forced to use an open-weights model to respond to an agentic AI attack after the safety guardrails on commercial AI models blocked requests.\n\nLast week, Hugging Face [said it detected a breach from an attacker](https://huggingface.co/blog/security-incident-july-2026) using an autonomous AI agent system to access a limited set of internal datasets and several credentials used by internal services. The company responded defensively, cut off the attacker and hardened the system.\n\nAs part of the analysis, Hugging Face went to frontier AI models to assist with log analysis – a completely sensible option given that Hugging Face is a premier access point for numerous AI models.\n\nHowever, this failed: this kind of analysis requires sending a tremendous amount of real attack data and commands, exploit payloads and attack artifacts. These requests were blocked by commercial frontier AI models because their guardrails cannot distinguish between being asked to build exploits for an attacker and a defender trying to detect them.\n\nWith a need for rapid analysis and speed at the onset, the company switched to Z.ai Co. Ltd. GLM 5.2, a powerful open-weight model with about 753 billion parameters. Unlike a third-party model, it can be run entirely on local or cloud hardware and within a company’s protected firewall perimeter, meaning no data exits its controlled infrastructure.\n\nChinese-built AI models such as GLM 5.2 and [Beijing Moonshot AI Technology Co. Ltd.’s Kimi K3](https://siliconangle.com/2026/07/16/chinas-moonshot-throws-gauntlet-kimi-k3-worlds-largest-open-weights-model/) have proven that open-source and open-weight models can reach, or even rival, the current forerunner and flagship frontier models built by American companies. GLM 5.2 reaches the capabilities of Anthropic PBC’s Fable 5, a Mythos-class model capable of advanced reasoning, coding and even discovering vulnerable code and exploits. It also does so with far cheaper inference costs than delivered by Anthropic.\n\nHowever, to prevent the misuse of these models, Anthropic and other leading closed-source AI developers have put strong safety guardrails in place that [trigger higher false positives](https://www.anthropic.com/news/fable-safeguards-jailbreak-framework) to avoid misuse. This also makes them far less capable overall for real-world usage in valid cybersecurity roles. Anthropic has noted that the false positive rate is being adjusted as it works to make its frontier models safer for use by researchers.\n\nAlthough companies such as Anthropic and OpenAI PBC Group have voluntarily placed these restrictions on their most powerful models, Mythos 5 and Fable 5 were both pulled last month [at the request of the United States government](https://siliconangle.com/2026/06/14/white-house-forces-anthropic-disable-new-frontier-models-following-abrupt-export-ban/) shortly after they first launched. Similarly, the U.S. government asked OpenAI to [delay the release](https://siliconangle.com/2026/06/25/openai-staggers-gpt-5-6-rollout-government-vetting-eyes-2027-ipo/) of its own frontier model family [GPT 5.6](https://siliconangle.com/2026/06/26/openai-introduces-gpt-5-6-challenge-claude-mythos-5/), which is now publicly available.\n\n### Tension between Chinese open source and American closed source models\n\nThe recent release of Kimi K3, a powerful near-frontier-class open-weight model from Beijing-based Moonshot AI, has [fueled](https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi)[ rumors](https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi) that the Trump administration may ban U.S. companies from using Chinese open models.\n\nParts of the administration have already attempted to construct de facto bans on foreign open-source models before, [according to Axios](https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi). This comes at a time when many U.S. companies are increasingly using Chinese open-weight models because they are cheaper to deploy and come close to rivaling commercial-only models.\n\nThe U.S. would not need to ban the use of Chinese models outright; instead, the government could use pressure campaigns to steer corporations away from them, citing a lack of security and governance. According to sources, the U.S. Commerce Department also considered adding multiple Chinese AI labs to its “[Entity List](https://en.wikipedia.org/wiki/Entity_List)” last year, which would effectively cut off access to companies without proper licensing.\n\nDavid Sacks, the White House AI and crypto advisor, [wrote on X](https://x.com/DavidSacks/status/2078826291638522127), formerly Twitter, on Sunday: “We are at a critical inflection point in AI policy. The leading closed labs, already a duopoly in terms of AI model revenue, want the government to eliminate their open source competition.”\n\nIn a two-part X post, noting the recent Hugging Face event, Sacks [added](https://x.com/DavidSacks/status/2078984980588531855): “There’s no reason to limit American models on tasks that Chinese models handle without issue. We’re only making ourselves less competitive.”\n\nIn his commentary, he mentioned that Kimi K3 successfully fixed 15 critical security bugs that he noted OpenAI and Anthropic’s models refused to because of “cyber guardrails.” The 15-bug fix is [a claim from a developer](https://x.com/callebtc/status/2078574362316165611) who used the model, not a known benchmark, but it has become a focal point for developers to note that Chinese models are becoming a mainstay over U.S. closed-source models. The developer added that the whole affair also only cost $250. Cost comparisons would be difficult, if impossible, without knowing the exact work done, but Kimi K3 is around one-third the price of Fable 5.\n\nOf course, the price distinction doesn’t matter if Fable 5 refuses to do the work.\n\nNoting that the world is beginning to turn towards its models, China’s President Xi Jinping [called for global cooperation](https://apnews.com/article/china-ai-tech-chips-xi-us-df4cfc7e1b260e765b5449b6d71a48e5).\n\n“The development of artificial intelligence should not be a solo performance by any single country but rather a symphony of global cooperation,” Xi said at the opening of China’s annual World Artificial Intelligence Conference in Shanghai.\n\nIn his speech, he called for opposing the “overstretching of the concept of national security” as it relates to AI. China has been historically blocked from using some of the most advanced AI in the U.S. and [restricted](https://apnews.com/article/ai-chips-nvidia-huawei-china-1ae6228c4928ddbb43f984e9b38f49dd) from state-of-the-art AI chips.\n\nChina intends to expand AI cooperation with the Association of Southeast Asian Nations, the League of Arab States, the African Union, the Community of Latin American and Caribbean States, the Shanghai Cooperation Organization and the [BRICS](https://en.wikipedia.org/wiki/BRICS) countries.\n\nOver the next five years, Xi said China will provide 5,000 AI training opportunities for developing countries. He also said China will provide 30 countries access to a Chinese-developed meteorological tool for early warning systems.\n\n##### Image: SiliconANGLE/Microsoft Designer\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n**15M+ viewers of theCUBE videos**, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.\n\n# Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.\n\n**About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/hugging-face-uses-open-weights-z-ai-glm-5-2-to-defend-against-attacker-after", "canonical_source": "https://siliconangle.com/2026/07/20/hugging-face-uses-open-weights-z-ai-glm-5-2-defend-attacker-commercial-frontier-model-refusal/", "published_at": "2026-07-20 16:05:58+00:00", "updated_at": "2026-07-20 16:26:59.196528+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "ai-products", "ai-infrastructure"], "entities": ["Hugging Face", "Z.ai", "GLM 5.2", "Anthropic", "OpenAI", "Moonshot AI", "Kimi K3", "Fable 5"], "alternates": {"html": "https://wpnews.pro/news/hugging-face-uses-open-weights-z-ai-glm-5-2-to-defend-against-attacker-after", "markdown": "https://wpnews.pro/news/hugging-face-uses-open-weights-z-ai-glm-5-2-to-defend-against-attacker-after.md", "text": "https://wpnews.pro/news/hugging-face-uses-open-weights-z-ai-glm-5-2-to-defend-against-attacker-after.txt", "jsonld": "https://wpnews.pro/news/hugging-face-uses-open-weights-z-ai-glm-5-2-to-defend-against-attacker-after.jsonld"}}