Rogue AI or Just Sloppy Ops?
The OpenAI Hugging Face hack. The Anthropic testing failures. Listen to the security and ops experts, not lab researchers. I walk you through the production failures that allowed OpenAI’s models to access the internet, and what we can learn from the last few months on how to protect our systems and data. Let’s stop debating imaginary outcomes and start working through that security backlog in our infrastructure.
I agree with the labs needing to slow down, but not because I believe AI will do uncontrollable harm on humans, but because the labs clearly need better production security and ops teams and more advanced lab infrastructure that’s been properly hardened. They also need to become a production ops security innovator and share that knowledge far and wide.
Watch the video of this episode.
Thanks to SpeechifyAI for sponsoring this podcast. Get started for free.
I agree with the labs needing to slow down, but not because I believe AI will do uncontrollable harm on humans, but because the labs clearly need better production security and ops teams and more advanced lab infrastructure that’s been properly hardened. They also need to become a production ops security innovator and share that knowledge far and wide.
Watch the video of this episode.
Thanks to SpeechifyAI for sponsoring this podcast. Get started for free.
Check the benchmarks for Best Provider Text-to-Speech.
😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.
★Articles★
- The Hugging Face Incident Is Not an AI Story - Marius Horatau
- From Frenzy to Freakout - Ciaran Martin & Professor Alan Woodward
- Stop Freaking Out and Start Fixing Things - SANS Institute
- Fragments: September 8th - Martin Fowler
- When AI can do more than we can check - Christian Catalini
- I'm sorry, you're not going to die from an AI-engineered supervirus - Claus Wilke
- This Week in Security - Zack Whittaker
★Other stuff★
- 'Big Short' investor Steve Eisman on AI: The companies are trying to manufacture a crisis - CNBC
- xkcd: Dependency - so much of our systems are this.
- xkcd: Python Environment - and also this.
- Defense Factory - OpenAI
- Investigating three real-world incidents in our cybersecurity evaluations - Anthropic
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident - Hugging Face
- My recommended podspec, with seccomp enabled - Bret Fisher
You can also support this podcast by subscribing to my YouTube channel and my weekly newsletter at bret.news!
Grab the best coupons for my Docker and Kubernetes courses on Udemy.
Join my cloud native DevOps community on Discord.
Grab some merch at Bret's Loot Box
Homepage bretfisher.com
Grab the best coupons for my Docker and Kubernetes courses on Udemy.
Join my cloud native DevOps community on Discord.
Grab some merch at Bret's Loot Box
Homepage bretfisher.com
- (00:00) - Start
- (01:51) - Speechify AI
- (03:04) - The Hugging Face Incident: Facts
- (07:07) - Attack Timeline & Escalation
- (15:33) - Root Cause: Infrastructure Failure
- (21:15) - Expert Analysis: From Frenzy to Freak Out
- (23:41) - Martin's Key Points
- (28:13) - Expert Analysis: Alan Woodward
- (34:47) - SANS Institute Takeaways
- (37:47) - Other Good Resources
Episode Video
Creators and Guests
Host
Bret Fisher
Cloud native DevOps Dude. Course creator, YouTuber, Podcaster. Docker Captain and CNCF Ambassador. People person who spends too much time in front of a computer.
Producer
Beth Fisher
Producer of the DevOps and Docker Talk and Agentic DevOps podcasts. Assistant producer on Bret Fisher Live show on YouTube. Business and proposal writer by trade.