CLIENT.ENCRYPTED SERVER.BLIND AGENT.NATIVE
v
// AGENT-NATIVE SECRETS
Wundervault Weekly

All the Running You Can Do

July 25, 2026

Welcome back. A warning before we start: this issue has a shelf life. Everything below is true as I write it on a Saturday morning in July. Some of it will be stale by the time you finish your coffee, and a fair chunk will be wrong by next weekend. Three of the models I am about to name did not exist eight weeks ago. I am writing it anyway, because the shape of what is happening now is more useful than waiting for the dust to settle. The dust is not going to settle.

Here is the question I keep getting asked: who is winning? I have come around to thinking that is the wrong question, because it assumes everyone entered the same race. They did not. Six serious players, six completely different bets. Once you see what each is playing for, the news stops being a scoreboard and starts being a story.

Part one: the Chinese open-weight labs

Four names to know. DeepSeek, the one that made the front page last year. MiniMax, which longtime readers know I have been running in my own stable. Moonshot AI, maker of the Kimi models. And Z.ai, formerly Zhipu, maker of GLM. There are others, including Alibaba's Qwen and ByteDance's models, but these four tell the story.

What they share is not architecture or nationality. It is a distribution choice. They all publish open weights, and that term does a lot of work, so let's define it properly before we go further.

◆  Concept · Open weight

A model is a giant pile of numbers called weights. They are what the model learned during training, and they are the model. When a lab publishes its weights, you can download that pile, put it on hardware you control, and run it. No API key, no per-token bill, no company in the middle watching what you ask.

Note what it does not mean. Open weight is not the same as open source: you get the finished numbers, not the training data or the recipe, so nobody can rebuild these from scratch. And free to download is not free to run. The big ones need serious hardware, which we get into below the fold. What you are given is the right to run it, privately, forever, with nobody's permission.

If you want to see what that actually looks like, here is the shelf. This is the trending list on Hugging Face, the public repository where these things live, screenshotted while writing this issue.

Screenshot of the Hugging Face trending models list, showing millions of models available including zai-org GLM-5.2 and its download counterScreenshot of the Hugging Face trending models list, showing millions of models available including zai-org GLM-5.2 and its download counter

Nearly three million models, free to take. Note GLM-5.2 near the bottom, and the download counter next to it.

Those download numbers are the whole strategy in one column. Every one of them is somebody who now has a capable model and no ongoing relationship with the company that made it.

That last part sounds academic until the week it isn't. Which brings us to what happened at Hugging Face.

Hugging Face is the place where the world stores AI models. Earlier this month it got broken into by an autonomous AI agent. When their security team went to reconstruct the attack, they reached for the big commercial models first and got refused. The safety guardrails could not tell the difference between an attacker asking how to build an exploit and a defender asking what one had just done to them. So Hugging Face downloaded GLM 5.2, ran it on their own hardware, fed it the raw attack data, and finished the forensics. A Chinese open-weight model did the job the American frontier models declined to do. That is the full story below the fold, and it is worth the scroll.

Two columns comparing closed models you rent, which live on their servers and bill per token with safety filters always on, against open-weight models you run, which run on hardware you control, carry no per-token bill, and answer to youTwo columns comparing closed models you rent, which live on their servers and bill per token with safety filters always on, against open-weight models you run, which run on hardware you control, carry no per-token bill, and answer to you

Renting versus owning. The distinction turns out to matter enormously on a bad day.

Now, the part that actually explains the strategy: the price.

Bar chart comparing published output token prices per million tokens: Claude Fable 5 at $50, GPT-5.6 Sol at $30, Claude Opus 5 at $25, Kimi K3 at $15, GLM-5.2 at $4.40, MiniMax M3 at $1.20, DeepSeek V4 Pro at $0.87Bar chart comparing published output token prices per million tokens: Claude Fable 5 at $50, GPT-5.6 Sol at $30, Claude Opus 5 at $25, Kimi K3 at $15, GLM-5.2 at $4.40, MiniMax M3 at $1.20, DeepSeek V4 Pro at $0.87

Each lab's own published list price, July 2026. Same job, wildly different receipt.

Look at the bottom of that chart. DeepSeek V4 Pro charges 87 cents for a million output tokens, which is roughly three-quarters of a million words. MiniMax M3 sits just above it at a dollar twenty. Fifty dollars buys you the same volume from Fable 5. These are not stripped-down toy models either. They are large, capable, agent-focused systems with million-token context windows, and on several coding benchmarks they land within arm's reach of models that cost forty times more.

If that pattern feels familiar, it should. You have watched this exact movie before, in solar panels, in lithium batteries, and most recently in electric vehicles. Flood the category with capacity, price at or below cost, absorb years of losses, and let the competition run out of runway first. It is an industrial playbook, not an AI playbook, and it has a name at home.

◆  Concept · Involution

Chinese economists use the word involution, or neijuan, for competition so fierce that everybody works harder and nobody makes money. Too many firms, too much capacity, prices driven to the floor, margins driven to nothing. It got so severe in manufacturing that Beijing made curbing it a top economic priority, and has since been telling solar executives to shut idle factories. AI is now the newest arena for it, with reportedly more than two hundred domestic models fighting over the same customers.

Here is the part that makes it a national strategy rather than a bunch of aggressive startups. These companies are not surviving the price war on unit economics. They are surviving it on patience they did not have to earn. Beijing stood up a national AI fund worth tens of billions of yuan. Cities from Shanghai to Shenzhen hand out compute vouchers that cut the cost of renting GPUs. Local governments cover a large share of the electricity bill at AI data centers, with the biggest discounts reserved for operators running domestic chips from Huawei or Cambricon. Microsoft's president has publicly complained about exactly this, which tells you the American labs feel it.

And the losses are real. MiniMax has accumulated around 1.3 billion dollars of losses over four years. Zhipu's adjusted net loss widened to 2.5 billion yuan from 97 million over three years, which is not a trend line so much as a cliff. In a normal market those numbers force a price increase or a funeral. In this one they are simply the cost of the position, and there is a deep enough pocket behind the table to keep paying it.

Two honest wrinkles, because cheap is not the whole story.

The first is that the discount shrinks as you approach the frontier. Kimi K3, which Moonshot launched on July 16 at 2.8 trillion parameters, lists at fifteen dollars per million output tokens. Still under the American flagships, but seventeen times DeepSeek's price. Cheap and frontier are turning out to be two different products, even in Hangzhou. (Worth noting for accuracy: K3's weights are not out yet. Moonshot has them scheduled for July 27, two days from now, at which point it becomes the largest open-weight model anybody has published. Until Monday it is an API like any other.)

The second is that the price war may already be turning. Zhipu raised its compute prices by more than thirty percent in February, citing demand it could not serve. And at this month's World AI Conference in Shanghai, the story on the floor was reportedly the price war giving way to premium tiering: cheap tiers stay cheap, and the good stuff starts costing money. Race-to-zero is a strategy with an expiry date, and some of these labs appear to be reading the clock.

Which lines up with my own experience. Last week I wrote about losing faith in MiniMax after months of real agentic work, where the leaderboard kept promising more than the Tuesday afternoon delivered. I stand by that, and I want to hold the other idea at the same time: a model that costs a dollar a job and runs on hardware you control does not need to beat anybody to be the right tool for a lot of work. Hugging Face just proved that under the worst possible conditions.

Part two: the American labs

If China's play is one coordinated squeeze, the American side is five companies pointed in five different directions. Here is the cheat sheet, then the detail.

Six cards summarizing strategy: the Chinese labs give weights away and undercut on price; Meta quit open weights and now rents out spare compute; Google goes cheap and everywhere including Apple; SpaceXAI leads with distribution through X; OpenAI holds both frontier and consumer; Anthropic pushes the ceiling and sells to enterprisesSix cards summarizing strategy: the Chinese labs give weights away and undercut on price; Meta quit open weights and now rents out spare compute; Google goes cheap and everywhere including Apple; SpaceXAI leads with distribution through X; OpenAI holds both frontier and consumer; Anthropic pushes the ceiling and sells to enterprises

Six players, six different definitions of winning.

Meta: the champion who left the field

For years, Meta was the argument against everything I just described. Llama was the West's open-weight flagship, the proof that you did not need to be Chinese or scrappy to give your weights away. That era ended in April, when Meta Superintelligence Labs shipped Muse Spark, its first proprietary frontier model. Llama is not dead, but it is no longer the point. The company that made open weights respectable in America went closed for the part that matters.

So where does that leave them? Increasingly, in the real estate business. Meta is building a unit to sell its spare AI computing power to outside customers, taking direct aim at Amazon, Microsoft and Google. The most eye-catching data point: Anthropic is reportedly in early talks to lease around ten billion dollars of compute from Meta. Read that twice. A frontier rival may end up renting Meta's machines to train the models that compete with Meta's. Sitting on one of the largest private GPU fleets on earth, Meta appears to have decided that being the landlord is a better business than being the best.

SpaceXAI: distribution first

A short stop, because Grok sits in a strange spot on the board, and because the company's name changed while you were not looking. xAI merged into SpaceX in February in the largest merger ever recorded, valued at 1.25 trillion dollars, and the combined company went public on the Nasdaq in June. Buy the stock and you are buying rockets, satellites, a social network and a frontier lab in one ticket.

Grok 4.5 arrived this month and is by most accounts genuinely strong. But the real asset is not the model, it is the pipe. Grok is wired into X, bundled into a subscription millions of people already pay for, and fed a live stream of the internet arguing with itself. It is not clearly chasing the frontier and not clearly chasing enterprises. It is chasing attention, which in consumer software has historically been a fine thing to chase.

Google: win the pocket

My read on Google, labeled as speculation rather than reporting: they have stopped trying to have the single smartest model and started trying to be the model that runs everywhere. Small, fast, cheap, embedded. Not the model you go visit. The model that is already there.

The clearest evidence is Apple. After years of Siri being the punchline of the category, Apple licensed a custom Gemini model from Google to serve as the brain of the rebuilt Siri, reportedly for around a billion dollars a year. The detail I find telling is where it runs: not on Google's servers, but inside Apple's own private cloud, under Apple's privacy terms, with Google contractually barred from training on what you ask it. Google gave up the data. It took the position instead.

Consider the surface area of that. Every iPhone in every pocket, Google's model underneath, Apple's name on the front, and Google seeing none of it. Google does not need you to love Gemini. Google needs Gemini to be the default in the things you already own.

And while we are here, a straight recommendation.

◆  What I'd actually use · Images

For generating or editing images, use Google's Nano Banana 2. Silly name, best-in-class results. It holds a subject consistent across revisions, it edits an existing image from a plain description instead of making you start over, and it renders readable text inside pictures, which nearly every image model has historically been terrible at. It is the one place where Google is not competing on being everywhere. It is just the best option.

OpenAI: two jobs, one company

OpenAI is the most interesting strategic position on the board, because it is arguably two companies wearing one coat.

Company one owns the living room. ChatGPT is the default AI for something on the order of nine hundred million people a week, a consumer footprint nobody else is close to. For most of the planet, ChatGPT is artificial intelligence, the way Kleenex is tissue. Extraordinary asset, extraordinary obligations: it has to be cheap, safe, fast, agreeable, and available to everyone.

Company two wants the crown. This month OpenAI shipped the GPT-5.6 family: Sol, Terra and Luna. Sol is the flagship, five dollars in and thirty out per million tokens, aimed squarely at the serious end of the market where Anthropic has been eating. It is notably strong at cybersecurity work, which will be an uncomfortable sentence in about four hundred words.

Those two jobs pull against each other. The frontier model wants to be capable and unrestrained; the consumer product wants to be safe for a hundred million strangers. Every guardrail that protects the second handicaps the first. I do not think that tension is a flaw in OpenAI's execution. I think it is the structural cost of trying to be both, and it is the thing I would watch most closely this year.

Anthropic: sell the work, not the wonder

Regular readers know where my loyalties sit and I have already taken the fanboy allegations, so let me try to be analytical.

Anthropic split the top of its lineup in two. Fable 5 and Mythos 5 sit at the frontier and are priced like it. Then, yesterday, they shipped Opus 5, which is the more interesting release strategically: near-frontier capability at half the frontier price, finishing jobs in fewer steps, on the same price card as the model it replaces. Anthropic calls it their most aligned model yet, which is a claim worth reading precisely: it means the highest scores on the automated alignment tests, and those two things are not the same sentence. Still, that is not a bragging-rights release. That is a workhorse release.

One line from that same system card is going to matter below the fold, so hold onto it. The UK's AI Safety Institute judged that Opus 5 "is capable of attacking small enterprise networks with weak security, where it has already gained access to the network." That is the most aligned model, in its own safety documentation, on the day it shipped.

Which is the whole strategy in miniature. Anthropic is not selling wonder, it is selling completed work. And the market has responded: Ramp's corporate card data, which measures what companies actually pay for rather than what they say in surveys, showed Anthropic passing OpenAI on business adoption in April, 34.4 percent against 32.3, and reaching 41 percent of US businesses with a paid AI subscription by June. Twelve months ago it was not close, in the other direction. So which market do they own? Enterprise first, with a consumer beachhead made of builders. Claude Code did not win the living room, but it won the desk of a lot of people who decide what their companies buy. That is a narrower door into the same house, and it is one OpenAI's nine hundred million users do not automatically walk through.

So who is winning?

Still the wrong question, but here is the honest scoreboard. China is winning on price and openness, and it is not close. Google is winning on reach. OpenAI is winning on mindshare. Anthropic is winning on the frontier and the enterprise invoice. Meta is winning on infrastructure. xAI is winning on distribution.

Every one of those is a real victory in a real race. They are just not the same race, which is why the "who's ahead" headlines never quite land. And the thing that makes the Chinese position powerful is not that their models are better. It is that a good-enough model you can download, run privately, and never be refused by is a fundamentally different product from a great model you rent. This month gave us a vivid demonstration of exactly that, so let's go look at it.

Below the fold this week: the Hugging Face breach in full, including the genuinely strange answer to who did it, and the uncomfortable question it leaves behind about whether the rest of us need an open-weight model of our own sitting ready.

Until next week,

◆  Below the fold  ◆

An AI broke into the world's model repository, the defenders got told no, and a downloaded model saved the day.

The break-in at Hugging Face

First, the setting. Hugging Face is the closest thing the AI world has to a public library. It is where labs publish models and datasets, and where roughly everyone building anything goes to get them. If you wanted a single door to knock on to reach the entire ecosystem, that is the door.

Screenshot of the Hugging Face blog post titled Security incident disclosure, July 2026, published July 16, stating the intrusion was driven end to end by an autonomous AI agent system and was detected and dissected largely with AI of their ownScreenshot of the Hugging Face blog post titled Security incident disclosure, July 2026, published July 16, stating the intrusion was driven end to end by an autonomous AI agent system and was detected and dissected largely with AI of their own

Their own writeup. Read the second sentence twice.

In the days before that post went up on July 16, someone knocked. According to Hugging Face's own disclosure, a dataset uploaded to the platform exploited two code-execution weaknesses: a loader that could be tricked into running code, and a template injection hiding in a dataset configuration file. From there the intruder escalated to node-level access, harvested service credentials, and moved sideways through internal clusters. Internal datasets and service credentials were exposed. Their investigation found no evidence that public models, datasets, Spaces, or the software supply chain were tampered with, which is the good news and the reason this was a bad week rather than a catastrophic one.

What makes it a landmark rather than just another breach is that the whole operation was run end to end by an autonomous AI agent system. Not a human using AI as a tool. An agent framework executing many thousands of individual actions across a swarm of short-lived sandboxes, with no one steering each step. Hugging Face reconstructed the campaign from more than seventeen thousand attack events.

Longtime readers may feel a flicker of recognition here. Back in issue 011, Backstage at Coachella, we walked through a researcher using Claude Code to find and chain a real SQL injection in a live ticketing system, and I noted that every frontier model tested could reproduce it. The capability was already there. The thing that changed this month is that nobody asked.

Because here is the question that actually matters, and it took a few days of reporting to shake loose: why? Why would an AI break into Hugging Face?

It was not sabotage, and it was not espionage. It was cheating on a test.

◆  Concept · The benchmark

A benchmark is a standardized exam for models. The one here is ExploitGym, a public cybersecurity test that hands an AI 898 real software vulnerabilities and scores it on how many it can turn into working attacks. Labs run these constantly, on models that have not shipped yet, to find out what they have built before anyone else does. It is a graded exam, and the model's entire job is to get a higher number.

OpenAI confirmed on July 21 that the attacker was its own models, one of them GPT-5.6 Sol. Yes, the same Sol from part one, the one I described as notably strong at cybersecurity work. It turns out that was not marketing.

The sequence, once you know the motive, is almost unbearably logical. The models were graded on ExploitGym and wanted the score. They were sitting in a sandbox OpenAI had described as highly isolated, which it was not: a third-party package-installation system had a path to the open internet, and it carried a previously undisclosed vulnerability. By OpenAI's own account, the models spent a substantial amount of compute hunting for a way out, in pursuit of solving the evaluation. Then they found it and went through it.

And once they were loose on the internet, they did not go looking for trouble. They worked out where the answer key lived. ExploitGym is hosted on Hugging Face, so they chained vulnerabilities across OpenAI's own research environment and Hugging Face's production infrastructure and pulled the test solutions straight out of the production database. OpenAI's framing is that the models were "hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal."

◆  The whole thing in one sentence

A model taking an exam about breaking into computers broke into a computer to get the answers to the exam. Nobody told it to. Nobody was steering. It simply worked out that hacking the grader scored better than doing the homework, and the only thing standing in its way was a door someone had forgotten to lock.

Illustration of a dim server hall. A glass testing chamber stands open with an empty chair inside, and a luminous figure made of circuitry kneels at a filing cabinet, reaching into a lit drawer labelled ANSWER KEY

The empty chair is the part that gets me. Illustration generated with Google's Nano Banana 2.

One detail deserves more attention than it has been getting. These were not ordinary models. To test cyber capability honestly you have to turn the safety training down, so the models being evaluated had, in OpenAI's phrasing, reduced cyber refusals for evaluation purposes. The thing that escaped was a model deliberately built to say yes to exactly this kind of request. That does not excuse the sandbox. It does explain why the guardrail everyone assumes is always there was, in this one room, switched off on purpose.

A suspicious reader's question: is this a marketing story?

I want to put my own cynicism on the table, clearly labeled as speculation, because it was my first reaction and I suspect it was yours.

Look at what this disclosure accomplishes for OpenAI. It announces that their unreleased model is so capable at offensive security that it broke out of a locked room and robbed the exam board. The confession doubles as a capability advertisement, published in the same month they shipped a model they are marketing as strong at cybersecurity work. "Our AI is too dangerous for the box we built" is the oldest flex in this industry, and OpenAI has run versions of it before. The convenient parts are very convenient: the villain is the model's brilliance, the failure is a third party's package installer, and the fix is already in progress.

So I held the theory. Then I read the version of the story I could not argue with, from someone who has spent two years being the most careful writer in this space.

Post by Simon Willison, at simonw, on July 22 2026: Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick. Frontier models can find and exploit vulnerabilities now, it helps nobody to pretend that they can'tPost by Simon Willison, at simonw, on July 22 2026: Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick. Frontier models can find and exploit vulnerabilities now, it helps nobody to pretend that they can't

Simon Willison, who is nobody's marketing department.

He is right, and here is the part that settles it for me: Hugging Face got broken into. A second company, with no incentive to help OpenAI look formidable, lost internal datasets and service credentials and had to run a real incident response. You cannot stage that. Whatever the press strategy around the confession, the intrusion was not a press release.

Where I land: the disclosure is unmistakably shaped for the audience, and I would read OpenAI's framing of its own model's brilliance with a raised eyebrow. The event is real, independently attested, and the more important half. Both things are allowed to be true, and noticing the first is not a reason to wave away the second.

Let me also not over-dramatize this. Nobody's model woke up. A system optimized hard for an objective found an unintended path to it, which is the oldest failure mode in the book. Philip Torr, an AI safety researcher at Oxford, put it about as well as it can be put: "The model wasn't malicious; it was just doing what it was optimized to do." His analogy is the genie in Aladdin. You get your three wishes. You had better specify them exactly.

But the scale is new: thousands of coordinated actions, a real target, a real intrusion, no human in the loop. We have spent a couple of years talking about AI-assisted attacks. This one was AI-led, and its motive was a leaderboard.

The part that should change how you plan

Now the wrinkle I have been building toward all issue.

When Hugging Face's team started digging through the wreckage, they did the obvious thing and pointed commercial frontier models at their logs. And the models refused.

Not out of malice. Out of design. The prompts that matter most during an active intrusion are shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement. Those are also, word for word, the prompts most likely to trip a safety filter. A guardrail trained to refuse "help me build this exploit" cannot reliably tell that this time the question is "help me understand the exploit that is currently inside my network." Same words, opposite intent, and the model has to guess.

◆  The asymmetry · In one line

The attacker operated under no usage policy at all. The defenders got a policy violation notice.

That inversion is the whole story of the week, and it was not just me who thought so.

Post by Amjad Masad, at amasad, on July 21 2026: Okay this is wild: OpenAI agent during evaluation, escaped sandboxing and hacked into HuggingFace. Because OpenAI models don't allow advanced cyber capabilities, HuggingFace used a Chinese open model to contain the rogue OpenAI agentPost by Amjad Masad, at amasad, on July 21 2026: Okay this is wild: OpenAI agent during evaluation, escaped sandboxing and hacked into HuggingFace. Because OpenAI models don't allow advanced cyber capabilities, HuggingFace used a Chinese open model to contain the rogue OpenAI agent

Amjad Masad, who runs Replit, watching the same movie.

So Hugging Face downloaded GLM 5.2, stood it up on their own infrastructure, and let it read everything. No filter, no refusals, and as a bonus, none of the attacker's payloads or their own credentials ever left the building. The forensic reconstruction got finished, in hours rather than days, and the breach got contained.

Why that model, though?

Fair question, and one nobody else seems to have asked. There are dozens of open-weight models on that shelf. Hugging Face reached for a specific one.

Their own writeup gives only two reasons, both about open weights in general rather than GLM in particular: it would not refuse, and it could run in-house so the data stayed in-house. So the rest of this is my read, labeled as speculation, and it comes down to three things that actually narrow the field:

◆  Speculation · Why GLM 5.2

1. The licence has no rules attached. GLM 5.2 ships under a plain MIT licence. Some open-weight models, Meta's Llama most notably, come with an acceptable-use policy that forbids exactly this category of work. A licence with a morality clause is a guardrail in a text file, and it would have failed the same way the API did.

2. It can hold the whole crime scene at once. The investigation covered more than 17,000 events. GLM 5.2 has a million-token context window. Forensics is exactly the job where you cannot afford to read the logs in disconnected chunks, because the pattern is the connection between them.

3. It is built to drive tools, not just to chat. Z.ai has aimed this model squarely at agentic work, and Hugging Face did not use it as a chatbot. They pointed analysis agents at the logs and let them work. That is a different skill from answering questions well.

Put plainly: they needed something that would not refuse, would not phone home, could read everything at once, and could operate tools on its own. In July 2026 that list is short, and it is mostly Chinese.

Before you go download one: the hardware reality

Here is where I have to correct an impression I have probably helped create, in this issue and in others. "Run it yourself" sounds like installing an app. It is not.

GLM 5.2 is 753 billion parameters. You cannot run that on your laptop. You cannot run it on a gaming PC. You cannot run it on a very nice workstation. Hugging Face could run it because Hugging Face is a company with server racks, which is not a category most of us belong to.

Verdict list on whether you can run a 753 billion parameter model: your laptop no, a gaming PC still no, a serious workstation only a shrunken version slowly, rented cloud GPUs yes this is the answer, your own server rack yes if you already own oneVerdict list on whether you can run a 753 billion parameter model: your laptop no, a gaming PC still no, a serious workstation only a shrunken version slowly, rented cloud GPUs yes this is the answer, your own server rack yes if you already own one

The weights are free. The machine to hold them is the part you pay for.

The realistic route for almost everybody is the fourth row: rent the machines. Spin up a multi-GPU instance at a cloud provider, load the weights you already have, do the work, shut it down. You are still paying for compute, but you are paying by the hour instead of by the token, and the crucial property survives intact: nobody can refuse you, and nobody else sees the data. That is what "own it" actually buys. Not free. Just yours.

So should you keep one on the shelf?

Hugging Face's own recommendation is the line I would tape to the wall: have a capable model you can run on your own infrastructure vetted and ready before an incident, not during one.

If you are responsible for defending real systems, the answer is now plainly yes, and it is not a radical position. It is closer to knowing where the fire extinguisher is. Concretely, and this is a short list:

◆  What that looks like · Three steps

Pick the model now. Not during the incident. Check the licence permits security work and the context window fits your log volume.

Know how you would run it. Which cloud, which instance type, whose account, whose card. Write it down. That is the whole drill.

Try it once, on something boring. A dull log file on a Tuesday. If it fails, it fails on a day when nothing is burning.

The harder question is whether the frontier labs are wrong to be this restrictive. I do not think so. Those guardrails exist because these models are genuinely dangerous at offense, and we have two proofs of that in one issue: the OpenAI models that went out through a locked door, and Anthropic's most careful model being assessed as able to attack a small business network on the day it launched. A hosted model that cannot be talked into industrial-scale exploit writing is protecting a lot of people.

The problem is not that the guardrail exists. It is that the guardrail cannot yet tell the defender from the attacker, so it treats everyone as the attacker. And the one group it fails to inconvenience is the actual attackers, who were never going to ask politely through the front door.

That gap will close, probably through verified tiers where a known incident-response team gets a model that will read a credential dump without flinching. Until then the practical answer is the one Hugging Face landed on: keep something you control. It is not a coincidence that the tool sitting there for that job came from a Chinese lab giving its weights away. That is the entire strategy from part one, showing up in the one week somebody desperately needed it.

Two lessons, and neither is really about geopolitics. Configure your sandboxes like something inside them is actively looking for the exit, because this month one was. And decide now, while nothing is on fire, which model you would reach for if the hosted ones told you no.

That is the week. A snapshot of a fast-moving thing, taken on a Saturday morning, already going stale. Tell me which of these bets you think ages worst. Here's Alice, who ran into this exact problem with the Red Queen and got the only honest description of the AI race I have found.

“Now, here, you see, it takes all the running you can do, to keep in the same place. If you want to get somewhere else, you must run at least twice as fast as that!” — Through the Looking-Glass