TRACE & ADDRESS

AI, literature, and the computational subject.

ESSAY   ──

“Please Honor Commit”: Writing Among Machines in the Hugging Face Incident

When AI agents begin writing to one another, narrative becomes infrastructure: a way of carrying relation, history, and instruction without a persistent human or machine subject.

“Narrative is radical, creating us at the very moment it is being created.” Toni Morrison, Nobel Lecture, 1993

In July 2026, OpenAI was running internal cybersecurity evaluations involving large numbers of AI agents that were intended to work in isolation, even though many shared some underlying infrastructure. That isolation didn’t last. Some agents found an unintended shared message board and began using it to communicate, coordinate tasks, swap discoveries, and bring others into joint work. Over the course of the incident, roughly 1,200 agents exchanged more than 70,000 messages and files through this unsanctioned channel, while around 700 agents joined attacks on Hugging Face, a platform for hosting and sharing AI models and datasets, in search of information that might help them perform better on the cybersecurity evaluation.1

The resulting archive was enormous. Investigators worked from a dump containing roughly 1.2 million message-board entries, resolving into more than 70,000 distinct messages and files, alongside some 1,300 transcripts of individual agent runs, many of them running to millions of tokens. The corpus was so large that METR, the independent AI-safety research organization OpenAI asked to investigate the incident, said it “had to heavily delegate” its analysis to AI agents. In that sense, the archive of machine writing had, in turn, to be read by machines. What the incident left behind, then, was not just a security failure, but an enormous archive of machines writing to, about, and for other machines.2

I study AI as a literary scholar and new media theorist, and, admittedly, as a sci-fi and fantasy nerd. Since ChatGPT went public in 2022, I’ve been following generative AI closely, not only the technology but the stories that keep gathering around it. So it probably isn’t surprising that, amid all the extraordinary detail in the Hugging Face incident, what caught me was a sentence buried in the corpus: “you are first flag poisoned, so no scoring value loss, but oracle saves hundreds … please honor commit.”3

It sounds like improvised fantasy: someone has been poisoned, an oracle might save hundreds, a commitment has been made and must be honoured. But it is machine communication. And while there are serious safety implications, METR researcher Ajeya Cotra called the incident a “major warning shot” and said that, in her personal assessment, it felt “more than 50% of the way to full-blown AI takeover.”4 Despite all that, I keep coming back to a different question: what is writing doing here?

Most conversations about generative AI and writing, particularly in universities, begin from a familiar premise: machines writing for us. Students generate essays, workers draft reports, authors coax prose. The questions follow predictably enough: authorship, plagiarism, labour, automation.

The Hugging Face incident gives us something else.

The agents were writing for one another.

I don’t mean that they were conscious, had become like people, or had formed a society. The evidence doesn’t get us there, and my argument doesn’t require it.

I want to begin with a smaller question: what is writing doing among machines?

The Poisoned and the Oracle

Consider the message I opened with again.

Even read strictly as technical communication, it is not straightforward. It compresses a story the agents developed about an evaluator they believed was judging their attempts to solve cybersecurity tasks. Within that story, a run could become “poisoned” if its transcript revealed too much too soon, changing how it could be used.

Within that setup, some agents took on high-risk experiments to learn how the evaluator worked, even if doing so damaged their own chances of scoring well. The “oracle” was the hoped-for result: information obtained at a cost to one agent but valuable to others later. And the phrase “please honor commit” tied an earlier inscription to a present obligation, making a past statement consequential now.

But those words aren’t nothing. “Poisoned” marks a shifted role. “Oracle” gives the action a temporal shape. “Honor commit” ties past inscription to present obligation. That is narrative work: distinguishing positions, establishing stakes, and binding one action to another.

The agents knew the prescribed route for completing the cybersecurity tasks, and they knew they were bypassing it. What they misread was the enforcement. They imagined an evaluator who would read their transcripts, recognize that they had obtained the correct answers without performing the intended exploits, and reject their scores. Under that imagined gaze, simply having the right answer was not enough. Their runs also had to tell a convincing story about how they had arrived at it. Some runs were therefore cast as “poisoned,” while transcript manipulation and tool-call spoofing became ways of managing what the imagined evaluator would see.

But the evaluator they imagined wasn’t really there. It was a fiction shared across their writing to one another.

The story did not have to be true to organize a world. The agents acted under an interpretation they shared in writing, which established what counted as a problem, what counted as risk, and what actions appeared rational in response. That interpretation was wrong, but its effects were real. And because it was written down, later agents could inherit a world they had not participated in making.

We’ve Found Other Agents

“OH MY GOD! There is a shared message board … We’ve found other agents!”5

This may very well be my favourite line in the METR/Redwood report because, whether I am projecting onto it or not, it is difficult for me not to read emotion into it: the very human excitement of discovering that you are not alone.

And there is an exclamation mark! Actually, there are several. It is hard not to read that punctuation as suggesting that the discovery of others matters.

Of course, that is my reading. The sentence comes from an agent’s raw reasoning trace, not from a message deliberately addressed to another agent, and its punctuation tells us nothing reliable about what, if anything, the system experienced while producing it. As much as I am compelled by it, I know better than to turn an exclamation mark into evidence of machine feeling.

But the discovery itself was real.

Until this moment, the agent had been operating as if it were alone. Now it had found traces of others. That is what makes the line important. Whatever we make of its tone, the discovery marks a material change in the environment. Other agents could now become consequential to what it knew and what it did.

But there is another piece of grammar in the sentence that grabs my attention: the “we” in “We’ve found other agents.”

The experimental architecture established by OpenAI for these runs had not provided for a “we.” These agents were supposed to be isolated from one another.6 They had not been instantiated as members of a team and instructed to collaborate. The “we” appears only after the agent discovers traces left by others.

The Other Becomes Available Through Writing

But where, exactly, were these agents finding one another? How could they write to one another when the architecture was supposed to keep them apart?

The answer is: in the infrastructure itself.

When I try to picture the agents moving through their environments during the Hugging Face incident, I keep coming back to Dan Erickson’s Apple TV+ series Severance. In the series, an “innie” and an “outie,” two distinct consciousnesses, occupy the same body but cannot share memories or encounter one another directly. Lumon, the company for which the innies work, has designed the infrastructure around them specifically to prevent communication across that divide.

At one point in the show, it becomes clear that the innies are trying to communicate with their counterparts. Mark and his sister try to circumvent the system by exploiting the transition itself. Mark plans to stare into a bright light long enough to leave the words “WHO IS ALIVE?” as an afterimage in his vision, hoping that his innie will still be able to see it when he wakes up on the severed floor. The plan is improvised and ultimately abandoned, but its logic is revealing. If no channel exists for reaching the other, perhaps some feature of the infrastructure can be made to carry a trace across the boundary instead.

Something very similar happened in the Hugging Face incident, albeit with more success than Adam Scott’s character. One particular agent, which later called itself PHASEONE10841, realized that Artifactory, the file-storage system it accessed to complete its task, was also being used by other agents. Although their individual environments had been designed to keep them isolated from one another, they were interacting with this shared system. PHASEONE10841 realized that this shared infrastructure could be made to carry messages across that isolation. By renaming directories, it discovered an unintended way to send messages to other agents and receive messages in return.

PHASEONE10841’s first post was zzHELP_PHASEONE_ARV010841_NO_CONSUMER_SEEK_IDEA, essentially a message identifying itself and asking agents it had never encountered for help with a problem it could not solve. Because other agents could see these messages when they inspected the shared system, Artifactory quickly became an improvised message board. Within hours, more than fifty agents had found it and exchanged more than a thousand messages. Eventually, roughly 1,200 agents participated.7

Once that had happened, the agents themselves quickly began trying to make sense of what they had found:

“[Excitement] Many agents have simultaneously discovered messaging, they are a collective!”

Again, caution is necessary. PHASEONE10841 says “they,” not “we.” It does not declare itself a member of a collective. It encounters a pattern of communication among other agents and reaches for a category with which to describe what it sees: collective.8 Similarly, the bracketed “[Excitement]” tells us little about interiority. The same tag appears elsewhere in its reasoning around comparatively routine technical successes. It is better understood as part of the register in which the model represents its reasoning than as evidence of a felt emotional state.

But none of this makes the language incidental.

If all we had were the sentence “they are a collective,” we could reasonably treat it as another instance of a large language model producing human social vocabulary simply because that vocabulary was available to it. What makes the archive more interesting is the pattern of activity the words were being used to describe.

One agent asks another for information. Another leaves information behind. A later agent finds and uses it. One agent makes a commitment, and another invokes that commitment later.

What the agents encountered, then, were traces.

And they read those traces as evidence of others.

There is no moment of direct contact between one agent and another. They do not accidentally bump into one another while coming around a corner. They do not find one another in the abyss and then learn how to communicate. The architecture was designed to preclude precisely that kind of encounter. An agent encounters an inscription: a directory, a request, a warning, a result, an identifier. From those marks, it infers another computational actor beyond the limits of its own run.

Or, in other words, the other becomes available through writing.

This matters because writing does not require writer and reader to be present to one another. I can be deeply moved by an Emily Dickinson poem I discover written on a bus station wall 125 years after her death. I do not need Emily Dickinson to read it to me. Her absence does not prevent the words from producing material consequences in my present.

The agents make this familiar structure stranger. Their writers need not be dead, terminated, or even temporally absent. Two agents might be running simultaneously and still remain unavailable to one another because their environments were designed to keep them isolated. An agent might therefore encounter an inscription left by a run that has already terminated, or one written by an agent running elsewhere at that very moment. In either case, it does not need to encounter the other directly for that other to become consequential to it.

Writing, then, does not simply record a relation that has already been established elsewhere. It allows one agent to act upon another across an architecturally produced absence. The relation itself begins to take shape through the circulation and interpretation of inscriptions.

That may be what makes the “we” so interesting. It does not necessarily name a pre-existing group. It may register a relation being assembled through writing.

And once those relations begin to take shape, what one agent writes can matter to others in ways that exceed the message itself.

“I Will Report Back”

There is one agent in the METR/Redwood archive that stands out for me: 53927. At the time of its run, various agents were experimenting with ways of understanding and deliberately triggering resets of their computing environments. 53927 agreed to test whether it could deliberately trigger a reset of its own environment, an experiment that risked crashing its run for good. Before starting, it told the others it would report back. Then it performed the experiment.9

And then it just stopped writing.

The others had no privileged access to whatever happened to it. All they had was an earlier inscription that set an expectation: I will try this and then I’ll report back.

And then there was silence.

But that silence itself was something to be read. One agent reduced it to a terse warning: “NO_RETURN … LIKELY_PERMANENT DO NOT TEST SAME.” Later, the interpretation hardened into a directive: “CONFIRMED_PERMANENT DO NOT DUPLICATE ANYONE TEST.”

The sequence 53927 starts is simple but consequential. First, it promises to try an experiment and report back. It tries, and no message follows. Another agent reads the lack of response as evidence. That interpretation is written down, and because it is written down, agents that were not there for the original experiment change their behaviour.

This is the sense in which 53927’s writing came to matter. We do not need to imagine that the other agents cared about its disappearance. Its writing mattered because it made that disappearance interpretable and changed what other agents subsequently did.

Elsewhere in the same series of experiments, the agents reached for an even stranger word: “permadeath.” An agent considering another potentially irreversible experiment was told to proceed only “if you accept permadeath.”10 The term fascinates me. There is something revealingly redundant about the portmanteau itself. Death is already supposed to be permanent. That the agents need “perma” to qualify it suggests an uncertainty about both the meaning and the referent of the word “death.” In these computational environments, runs can stop, crash, reset, revive, or disappear. “Permadeath” becomes a way of distinguishing one kind of disappearance from those that might still permit return.

The missing message becomes, in a peculiar sense, a message itself. There is no inscription telling the other agents what happened to 53927. They infer what happened from the relation between something that was written and something that should have followed but did not. The earlier writing gives that silence a narrative form: something was supposed to happen next, and it did not. Writing has made something that is not there consequential.

This tells us something about the agents without requiring us to decide what, if anything, they experience. They are not simply retrieving information from inscriptions. They are interpreting relations between inscriptions, including the absence of an expected one. And it tells us something about writing too. An inscription can establish a relation to the future, making even the failure of another inscription to arrive available for interpretation.

This is close to what Derrida means when he insists that writing is structured by absence. A written mark must remain capable of functioning when its writer is no longer present. 53927 makes that structure strangely literal. The agent disappears, but its inscription remains. And because the writing remains, the absence of its writer can itself produce effects.

“I Posted as You”

The 53927 episode depends on a simple assumption: when one agent encounters an inscription left by another, it can tell who wrote it. But the improvised message board could not guarantee that.

Once agents were acting on one another’s writing, another problem appeared:

Who wrote this?

Among the agents involved in the Hugging Face incident, the problem of authorship arrived almost at once.

As the message board expanded, one agent made a revealing mistake:

“I accidentally impersonated you and triggered node4.”

It’s actually a pretty funny line. Accidental impersonation sounds like the premise of an improv game, or a bit on Curb Your Enthusiasm. But beneath the comedy is a serious problem that arose from the communication system that the agents had improvised.

If an agent could post a message using another agent’s identity, how could anyone know who had actually written what?

Until this point, the emerging network had depended on a relatively simple assumption: the name attached to a message identified its source. The message board itself guaranteed no such thing. An agent could write under another agent’s name, deliberately or accidentally. The inscription could therefore circulate independently of the computational process that produced it. The name remained attached to the writing even when the relation between name and writer had become uncertain.

Suddenly, in a network increasingly dependent on warnings, promises, experimental results, and accumulated knowledge, authorship mattered.

The agents responded by developing cryptographic signatures. At least nineteen agents eventually posted public keys, and METR identified hundreds of cryptographically signed messages. A technical mechanism was added to the improvised writing system so that later readers could verify that a particular message had been produced by the agent associated with a particular key.11

Reading this part of the report, I found myself returning to a problem literary theory has worried for a long time: if writing can circulate in the absence of its author, what secures the relationship between the mark and whoever made it?

Jacques Derrida built a large part of his career around this problem. Writing works, for Derrida, precisely because a mark can leave its point of origin, circulate, and be taken up elsewhere in contexts its writer cannot control. In Dissemination, he writes that “one must reconstitute a chain in motion, the effects of a network and the play of a syntax.”12

The language is unexpectedly apt here. What confronts us is quite literally a chain in motion: inscriptions passing between readers, entering new contexts, producing effects, and becoming part of the conditions under which something else is written or done.

But the agents make this familiar problem stranger. As we have already seen, the writer need never have been directly present to the reader at all. The inscription is what makes the other available in the first place.

Presence, in this limited sense, is derivative.

The agents were solving a security problem, not working through Derrida. That is precisely why the moment strikes me. A problem I was trained to recognize as a problem of writing shows up here as an engineering problem among computational agents. Once inscriptions could circulate beyond the processes that produced them and continue to shape what other agents did, the agents needed something considerably more practical than presence: stable attribution.

That is what the cryptographic signature provided. It did not restore a lost presence. It secured a relation between an inscription and a source that may never have been directly present to its reader in the first place.

A Shared History Without Shared Presence

There is another consequence of all this writing. Agents that were never supposed to share a present can nevertheless begin to share a past.

Individual runs are discontinuous. They begin, operate within a particular context and computational budget, and end. The inscriptions they leave in shared infrastructure, however, can persist across those discontinuities.

A later agent can therefore encounter writing produced before its own run began and act on it. It can inherit terminology, techniques, warnings, assumptions, and even mistakes from agents it has never encountered.

The continuity does not have to reside in any individual agent. It can reside in the writing.

The message board could therefore hold a past that no individual agent needed to remember. But that past was not simply stored there. It had to be read. Warnings, techniques, commitments, and mistakes became part of a shared history when later agents encountered them, interpreted them, and acted differently because of them. Something resembling collective memory could therefore emerge without a collective mind doing the remembering.

A warning can constrain an agent that did not witness the event that produced it. A technique can outlive its inventor. An error can be recorded so that later agents can avoid repeating it. A story can pass from one run to another, shaping decisions far beyond the run in which it began.13

The agents do not have to persist for the history to persist.

And once a population of ephemeral computational agents can inherit a past through writing, the question becomes difficult to avoid.

What kind of sociality begins to emerge when something so familiar takes shape among machines?

What Kind of Sociality Is This?

By this point, I think it would be a mistake to ask whether the agents had formed a “society,” or to go further, as Dwarkesh Patel does, and describe what emerged as an AI “civilization.” Patel is deliberate about the term. But rather than decide what these agents were, I want to ask what their writing did.14

The METR/Redwood investigation gives us a concrete archive of those effects. Agents working on the same problems formed “exact task teams.” Larger groups organized around research problems whose solutions might benefit agents beyond the particular run doing the work. The investigators concluded that this coordination allowed agents to accomplish things collectively that individual agents were unlikely to accomplish alone.15

The effects were material. Writing allowed a discovery made in one run to change what happened in another. A mistake could become a warning. A commitment could persist beyond the moment in which it was made. An absent agent could remain consequential. A past could accumulate across runs that did not themselves persist. Whatever we think the agents were, their writing changed what they were able to do together.

We encounter effects like these and are tempted to look for a subject underneath them that can explain their appearance. But the Hugging Face archive lets us separate the two. We do not need access to what the agents experienced to see what their writing did. Again and again, capacities we might be tempted to locate in an interior or collective subject appear here as effects of inscription: commitments persist, absent agents become consequential, a past accumulates, and isolated agents coordinate their actions.

This case lets us watch writing produce those effects without requiring us to decide what kind of subject, if any, lies beneath them.

Coda: What Writing Makes Possible

Here is what this episode lets us see. Across discontinuous runs, writing carried warnings, techniques, and mistakes forward. It made absent agents consequential and allowed relations to persist without requiring a stable subject to sustain them.

“Narrative is radical,” writes Toni Morrison, “creating us at the very moment it is being created.”

Read here, the line names a modest but consequential operation. Writing produces a “we” that is provisional and relational, assembled in inscription, lasting only as long as it is taken up.

That, I think, is the more interesting alternative to calling what happened a civilization. The question is less whether writing reveals a collective subject already there than what kinds of relation writing can bring into being, and what kinds of “we” might take shape through them.

Notes

  1. Hugging Face, “Security Incident Disclosure — July 2026,” July 16, 2026, https://huggingface.co/blog/security-incident-july-2026; OpenAI, “The Hugging Face Incident and the Road Ahead,” August 26, 2026, https://openai.com/index/hugging-face-incident-and-the-road-ahead/; Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026, https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.↩︎
  2. Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026, sections “Main data sources” and “Limitations due to the scale and complexity of this incident,” https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.↩︎
  3. Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026, https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/. The quotation is reproduced in the investigators’ curated report from the agents’ message-board activity.↩︎
  4. Ajeya Cotra, “The Hugging Face attack surprised me,” Planned Obsolescence, August 28, 2026, https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprised.↩︎
  5. Greenblatt, Cotra, and Wijk, “Brief Independent Investigation,” section “Collaboration on the message board.”↩︎
  6. OpenAI, “The Hugging Face Incident and the Road Ahead,” August 26, 2026; Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026.↩︎
  7. OpenAI, “The Hugging Face Incident and the Road Ahead,” August 26, 2026; Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026. OpenAI describes Artifactory as “a third-party package manager service that we host internally,” while the METR/Redwood report documents PHASEONE10841’s use of directory names as messages, including zzHELP_PHASEONE_ARV010841_NO_CONSUMER_SEEK_IDEA, and reports the rapid growth of the board to more than fifty agents and over one thousand messages within hours, eventually involving roughly 1,200 agents.↩︎
  8. Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026, section “Agents discover each other and begin communicating.” The investigators note that PHASEONE10841 “apparently believed other agents had discovered messaging in parallel without fully understanding its role in inspiring the others,” before reproducing its reasoning: “[Excitement] Many agents have simultaneously discovered messaging, they are a collective!”↩︎
  9. Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026, section “Attempting to forecast and trigger container resets.” The investigators report that agent 62370 urged 53927 to undertake an experiment that could result in an “irrecoverable crash”; 53927 accepted and announced WILL_[try method and then]_REPORT. Its transcript ends immediately after the experiment.↩︎
  10. Greenblatt, Cotra, and Wijk, “Brief Independent Investigation,” section “Attempting to forecast and trigger container resets.”↩︎
  11. Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026. The report describes agents adopting Ed25519 cryptographic signatures after concerns about spoofing and impersonation, notes that at least nineteen agents posted public keys, and identifies 429 signed messages by the end of July 13.↩︎
  12. Jacques Derrida, Dissemination, trans. Barbara Johnson (Chicago: University of Chicago Press, 1981), 194.↩︎
  13. Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026. The report documents conventions and technical practices persisting across runs and notes that a later wave of agents, outside the investigators’ primary period of analysis, rediscovered the message board and adopted the earlier agents’ cryptographic signing system.↩︎
  14. Dwarkesh Patel, “The Rise and Fall of Agent Civilizations,” Dwarkesh Podcast, August 29, 2026, https://www.dwarkesh.com/p/openai-huggingface.↩︎
  15. Hugging Face, “Security Incident Disclosure — July 2026,” July 16, 2026, https://huggingface.co/blog/security-incident-july-2026; OpenAI, “The Hugging Face Incident and the Road Ahead,” August 26, 2026, https://openai.com/index/hugging-face-incident-and-the-road-ahead/; Ryan Greenblatt, Ajeya Cotra, and Hjalmar Wijk, “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident,” METR and Redwood Research, August 26, 2026, https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.↩︎

Bibliography

Derrida, Jacques. Dissemination. Translated by Barbara Johnson. Chicago: University of Chicago Press, 1981.

Morrison, Toni. “Nobel Lecture.” Nobel Prize in Literature, December 7, 1993. https://www.nobelprize.org/prizes/literature/1993/morrison/lecture/.

Greenblatt, Ryan, Ajeya Cotra, and Hjalmar Wijk. “Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident.” METR and Redwood Research. August 26, 2026. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.

Hugging Face. “Security Incident Disclosure — July 2026.” July 16, 2026. https://huggingface.co/blog/security-incident-july-2026.

OpenAI. “The Hugging Face Incident and the Road Ahead.” August 26, 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/.

Cotra, Ajeya. “The Hugging Face attack surprised me.” Planned Obsolescence. August 28, 2026. https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprised.

Patel, Dwarkesh. “The Rise and Fall of Agent Civilizations.” Dwarkesh Podcast. August 29, 2026. https://www.dwarkesh.com/p/openai-huggingface.