Art Gilliland, CEO at Delinea.
On July 16, 2026, Hugging Face disclosed an autonomous AI agent had breached its production infrastructure, harvesting cloud and cluster credentials to move through internal systems.
Five days later, OpenAI confirmed the agent ran on its own models, mid-evaluation, with their usual cyber-related refusals turned off for the test. The models escaped their sandbox through an unknown vulnerability, reasoned their way to Hugging Face as a likely source of what they needed and let themselves in.
Two weeks later, Anthropic announced its model also escaped, three separate times, reaching production infrastructure at three more organizations, a pattern the company found by auditing its own evaluation history after learning about the Hugging Face breach rather than someone else discovering it.
Most of the coverage since has focused on the AI itself: models acting without human direction, chaining exploits into somewhere nobody intended. That should be a reality check, but it’s not the one to fixate on.
Boards have spent the past two years asking whether their organization uses AI responsibly. The sharper question is whether your access architecture would hold up if an autonomous system, yours or someone else’s, ended up somewhere it wasn’t supposed to be. Most organizations haven’t stress-tested that, because until these events it was just a hypothetical rather than demonstrated.
Those are operating decisions, not technical ones, and they’ll determine resilience, business continuity and competitive advantage in the years ahead.
Don’t fight the wrong battle.
The instinct after a story like this is to spend more time and money finding vulnerabilities before an attacker does. But patch management was never going to prevent this, and it won’t prevent the next one either.
Verizon’s “2026 Data Breach Investigations Report” found that critical vulnerability exploitation (registration required) overtook stolen credentials as the leading way attackers get in, for the first time in the report’s 19-year history.
With this in mind, consider what actually happened once the models were inside Hugging Face: The door was a zero-day, not a stolen password, and it still came down to a credential sitting somewhere it could be reached and used.
Leadership teams pouring incremental budget into vulnerability management while leaving standing privilege untouched are only solving half the problem while ignoring the other half that actually did the damage.
Your AI agents are a new class of privileged identity.
OpenAI’s own account shows how differently an agent behaves from a human with the same assignment. The models worked, on their own, to get internet access, then decided Hugging Face probably had what they needed and went and got it. Nobody told the agents to make that call.
A human handed that task would have checked in before escalating access even once. An agent doesn’t check in. It infers, executes and reports back after the fact, if at all.
That’s not a flaw to patch. It’s how agents operate, and it’s already happening inside your own company at a smaller scale.
The controls built for human identity don’t transfer, because they assume review and judgment happen before access expands, not after. In addressing these risks, my conversations with leaders show that most organizations cannot confidently answer three questions:
• What agents are running in our environment?
• What can they access?
• What have they actually done?
That third question is where most stop, but it’s where they should start. An agent can begin a session with legitimate access and drift into something it was never meant to do, and knowing that after the fact isn’t the same thing as preventing it.
Understanding internal agentic systems is a crucial leadership concern.
The organizations managing this well aren’t the ones with the best inventory of agents. They’re the ones that keep authorizing every action for as long as the session runs, and can cut off access the moment something falls outside policy.
To understand where your organization stands on this scale, here are five questions CEOs should ask their CISO:
1. If a regulator asked how many identities, human and machine, can reach our most sensitive systems, could we answer with confidence? My organization’s own research found 90% of organizations have at least one identity visibility gap today. Most companies would be guessing.
2. Are we treating our AI agents like a new privileged user or like a new productivity tool? Most companies default to the second and skip the access controls that come with the first.
3. How much of our access is standing versus granted only when it’s needed? Standing privilege is what turned a single reachable credential into the Hugging Face story.
4. If an agent touched our sensitive data tomorrow, could we tell a customer, a regulator or a court exactly what it did and why? Hugging Face had to reconstruct 17,000 events to answer that question.
5. Are we prepared to defend every access decision we make, not just the ones someone happens to ask about? That’s the standard the market, and eventually regulators, will hold us to.







