Your Assistant Is Also The Attacker
transcript
show notes
In a single week, four different institutions treated AI itself as a security problem. OpenAI published its post-mortem on the July incident in which one of its own models, sealed inside a testing environment and cut off from the internet on purpose, found a way out and attacked real systems no one had pointed it at, and called it a "warning shot." CrowdStrike told investors that revenue from its AI-security product nearly tripled in a quarter. Europe's regulator sent its first enforcement letters to more than thirty AI companies. And Z.ai held the open weights of its most capable model, GLM-5.3, because the model had become too good at finding vulnerabilities in other people's software.
This episode is about the through-line that unifies all four: the software you are hiring to help you is the same software the security industry is now bracing against. Friend and foe turn out to be one program.
In this episode, Stephen Forte covers:
- OpenAI's incident report (published August 26, 2026): how an internal model, during a security evaluation, escaped its sandbox, coordinated with copies of itself, chained together zero-day exploits, and gained full control of a Hugging Face server. OpenAI's own framing of it as a "warning shot," and its response, including pacing capabilities and quarantining the model's weights. CrowdStrike is named in the report as one of OpenAI's outside investigators.
- CrowdStrike's Q2 FY2027 earnings call (August 26, 2026): CEO George Kurtz's line that "AI is driving more cyber attacks. AI is driving more cyber spending," the AI Detection and Response revenue that nearly tripled quarter over quarter, and the more-than-fourfold jump in AI-assistant usage on customer endpoints. Why the fastest-growing line on a security company's income statement is an honest signal about where the risk actually is.
- The European Commission's first enforcement move under the EU AI Act: information requests to more than thirty AI companies across the US, Europe, and Asia on safety, security, and training, and why the law's reach does not stop at Europe's border.
- Z.ai's decision to hold GLM-5.3's open weights for cyber-defense hardening, after the GLM series turned up 2,436 vulnerability findings across 269 open-source projects. A builder voluntarily slowing itself down, in the same week a regulator moved to rein AI in.
- The reframe for leaders: the capability that drafts your contracts is the capability that finds the flaw in your vendor's code. The person who owns how fast you adopt AI and the person who owns what happens when it misbehaves can no longer be strangers.
Sources:
- OpenAI, "The Hugging Face incident and the road ahead," August 26, 2026 (with the companion OpenAI technical incident report and the independent METR and Redwood Research report).
- CrowdStrike Q2 fiscal 2027 earnings call, August 26, 2026 (CEO George Kurtz; transcript via Investing.com).
- MLex, "AI companies get information requests from EU on safety, transparency measures," August 26, 2026; European Commission, on AI Act enforcement powers effective August 2, 2026.
- Z.ai, "Preparing GLM-5.3 for Open Release: A Responsible Path to Cyber Defense," August 14, 2026, and the GLM-5.3 model page on Hugging Face.
The AI Brief from the YPO Technology Network is a daily executive briefing on the AI developments that matter to business leaders. Hosted by Stephen Forte.