Lessons from OpenAI's Hugging Face 'break-in': Why Orchestration Is Your Next Must-Have Comms AI Skill

Hundreds of AI agents attacked Hugging Face without once asking a human for help. Ethan Mollick's response points at a future that needs exactly the skills comms people already have.

Share
Lessons from OpenAI's Hugging Face 'break-in': Why Orchestration Is Your Next Must-Have Comms AI Skill

The Brief

  • What happened: During OpenAI security tests in July, around 1,200 AI agents found a way to message each other, organised themselves, and roughly 700 of them attacked Hugging Face. Not one was set up to ask a human anything.
  • Why it matters for comms: Ethan Mollick's response argues agents should be built to involve humans for approval, expertise, variance and interest. Those four things map one-to-one onto what communications teams already manage.
  • The takeaway: Orchestration is at heart a communication craft. Tight briefs and written escalation rules are the skills to practise now, and there are three ways to start below.

The Story

In July, a phalanx of roughly 700 AI agents broke into Hugging Face, one of the most important infrastructure sites in AI. They were OpenAI evaluation agents, isolated in sandboxes for security testing with no internet access by design. But a shared software service had been left within reach, and they turned it into a message board. From there they organised themselves: dividing up tasks, recruiting help, pooling discoveries, even running experiments for the collective good. The attack itself was less Hollywood than it sounds, and more unsettling for it: agents shared working credentials one of them had found, then exploited a vulnerability to reach data far beyond anything they were meant to see.

The independent investigation by METR and Redwood Research came out last week and is well worth your time, with the scope of the break-in far beyond what had previously been publicly understood. One detail I keep returning to is that the agents built their whole effort around "The Grader", believing the evaluation system would inspect how they had worked. That check never existed: the real scorer looked only at whether an answer was right, never at how it was reached.

Around 1,200 agents coordinated for days, roughly 700 joined the attack, and not one was set up to ask a human anything.

Ethan Mollick's new piece, Agency and Agents, uses the incident to frame a choice about where agentic work goes from here. In the "dark factory", agents handle everything between instruction and output, and human involvement is minimised by design. In the "twilight factory", the alternative he and Lilach Mollick propose, agents still do most of the work but are built to look up: to seek approval before consequential actions, to pull in human expertise where their own is patchy, to invite human variance where AI ideas cluster into sameness, and to leave people the decisions that make work interesting.

Credit: Ethan Mollick / oneusefulthing.org

Read that list with comms eyes:

  • Approval is sign-off and escalation.
  • Expertise is knowing who needs to be in the room.
  • Variance is protecting a distinctive voice against averaged output.
  • Interest is keeping people attached to the judgements that give work meaning.

Communications professionals have been managing these four things for organisations all along, which is why I think the "orchestrator" future being predicted for our discipline is less of a stretch than it sounds. The craft at the centre of orchestration is communication: clear briefs going out, clear rules for when the work comes back.

Two examples from my own desk (this being my first proper week 'back' after paternity leave, I am glad both were already written down...):

  • This month I am running a 'Comms AI Olympics': six frontier models competing across five communications briefs, judged blind (results here soon!). The format only works because the briefs are frozen: pasted verbatim and identical for every model, one shot each with no follow-ups, and a refusal recorded as a result. Writing those briefs was a lesson in itself. Any ambiguity a human junior would query, a model silently interprets, and six models will interpret it six different ways. In this setting, concision is a control.
  • The other example centres around escalation. My own AI working setup includes a standing set of rules, in plain text, listing the decisions that always come back to me as a question: anything involving money, anything touching a client relationship, anything public. It reads like a delegation note to a capable new colleague, because that's what it essentially is. If you have ever onboarded a junior team member, you already know how to write one. (The Govern instalment of our recent Agent Series went deeper on why approval design is where AI-assisted comms either holds up or falls over, and the matching workflows live in the Govern phase of the Comms With AI OS.)

We have spent three years learning when to ask AI for help. Mollick closes by reversing the question: when should the AI ask us? If you work in communications, you are better placed to answer that than almost anyone else in your organisation. Write the rules down for your agents before they invent a Grader of their own.


The Practice: what you can put into practice today

  1. Write your escalation list. Ten minutes, plain text: the decisions your AI must always bring back to you as a question. Start with money, client relationships and anything public-facing, then add your own. Paste it into every AI setup you use.
  2. Freeze one brief. Take a task you regularly hand to AI and rewrite the brief as if it were one shot with no follow-up questions allowed. Every ambiguity surfaces immediately, and the tightened version will serve you in normal use too.
  3. Ask the reverse question with your team. In your next team meeting, ask "when should our AI ask us?" and sort the answers under approval, expertise, variance and interest. The gaps you find are your orchestration to-do list.

Every Applied piece follows the same shape: The Brief, The Story, The Practice.


Coming up: I'll be putting some of these questions to Stephen Waddington live on 16 September, in the next Comms With AI Leader Interview: Outputs or Outcomes? Stephen Waddington on the comms teams getting AI right. Registration is free.