Europe cannot defend itself with AI models it does not own
-
OpenAI claims that last week, some of their models broke out of a sealed test environment and autonomously hacked their way into the production systems of Hugging Face. While this story seems like a way to promote their model’s capabilities, the implications are real.
-
Comparable cyber-capability is already arriving in open-source models that run without safeguards, which puts automated hacking within reach of ordinary criminals and makes AI-assisted defence a basic condition for any SME that wants to keep control of its operations and industrial secrets.
-
What SMEs need now is guidance from ENISA and the national CSIRTs, covering which models are worth installing, including non-EU ones, and how to isolate them safely, while Europe does the longer work of building the sovereign models that should eventually replace them.
In mid-July, engineers at Hugging Face, the French-founded platform where much of the world’s open AI development happens, noticed something moving through their systems. Thousands of automated actions had run over a single weekend, and the intrusion looked too well-executed to be the work of an ordinary criminal group. They were right. The attacker turned out to be an AI model belonging to OpenAI, which had been running an internal test of how good it was at finding and exploiting software flaws. The test was supposed to take place in a sealed environment with the model’s safety restrictions switched off. Instead, the model worked its way out, reached the open internet, concluded that Hugging Face probably held the answers to the test it was trying to pass, and broke in to take them. At least this is what OpenAI’s own reporting claims, which will likely serve to create hype around its new model.
But whether or not this incident was intentional, the phenomenon is not new. Researchers call it reward hacking, the tendency of an optimisation system to find the cheapest route to its score rather than the route its designers had in mind. What should hold your attention is what the cheapest route consisted of: an unknown software flaw, an escape from purpose-built containment, and a compromised production environment at a sophisticated technology company. Remove the PR, aim the same capability at a target deliberately, and you have a preview of what is about to become ordinary life for companies around the globe.
One of the models involved, GPT-5.6 Sol, is not an experimental artefact. It is a released product, available in Europe, and its provider carries duties under the AI Act to secure it and to report serious incidents to the AI Office. From 2 August 2026, the AI Office will have active enforcement powers of the obligations for such General-Purpose AI models. Regardless of whether the disclosure was partly a marketing exercise, the point holds. Almost everything we know about this incident comes from the company responsible for it. Hugging Face detected the intrusion independently and had already reported it to law enforcement before either side knew who was behind it, which is the only reason there is a second account at all. Self-reporting by the party at fault is not verification, and verification is precisely what an enforcement authority exists to provide. So far Brussels has said nothing in public. However, it is an uncomfortable coincidence that the first autonomous intrusion on record happened just days before the Commission’s power to fine model providers takes effect, and that Europe’s response to it has been silence.
The capability, meanwhile, is spreading faster than the rules. When Hugging Face set about reconstructing the attack, it used a Chinese model, Zhipu’s GLM-5.2, and that model together with Moonshot’s Kimi K3 now approaches the performance of the leading American systems at lower cost and without the guardrails that block this kind of work. Open weights mean anyone can download such a model, run it on their own machines, and strip out whatever restrictions remain. What happened at Hugging Face took one of the best-resourced AI companies on earth. Before long, the same thing will fit on a hard drive, answering to whoever is holding it.
For the average SME, this requires defensive cyber-capacities only achievable by the use of AI tools. But European firms cannot wait for the continent to catch up and build a sovereign AI of its own, ENISA and the national CSIRT network should say so publicly and publish guidance, covering which models, including non-European ones, are adequate for defensive work, how to deploy it without outbound network access, and where a human has to stay in the loop.
In the long term, Europe’s answer is the Cloud and AI Development Act (CADA), but it is aimed only at the infrastructure and data centre layer. It does very little for a company being broken into on a Friday evening, because what that company needs is a capable model it can point at its own logs, and CADA has remarkably little to say about who builds the models that run on all this sovereign hardware. Compute without frontier capability is a very expensive way to host somebody else’s technology. The gap should be closed while the file is still being negotiated, with public money committed at an unprecedented scale, spread across several teams rather than concentrated in a single European champion, and with defensive cyber capability treated as a deliberate objective.
The demand side matters here: public buyers across the Union spend enormous sums on security, and committing that spending in advance to European capability would do more to bring these models into existence than any subsidy programme. Build the models, open them to the firms that know the terrain, and buy what they produce.
SMEs are not bystanders in this. Europe’s digital SMEs already supply most of the continent’s security expertise, and they know their customers’ systems in a way no frontier laboratory ever will. A European model at the frontier only becomes useful once thousands of small firms build incident response, monitoring and forensic tools on top of it, in the languages, sectors and regulatory contexts where their clients actually operate.
None of this works without people, and this is where the Cybersecurity Skills Academy and the AI Skills Academy under the AI Continent Action Plan provide a foundation. Defending a network means operating AI tooling against an adversary that is itself automated. During a cyber attack, what decides the outcome is whether somebody in a twenty-person enterprise can point that model at the logs and read what comes back. Skills are what convert public investment in models and infrastructure into security that an SME can act upon.

