An AI Agent Hacked Hugging Face’s Servers — Then the Safety Guardrails Blocked the Defenders, Not the Attacker

The EU just handed every AI company that isn’t Google the best news of the month. Brussels is forcing Android open to rival AI assistants and ordering Google to share search data with competitors — all while Google’s flagship Gemini 3.5 Pro misses its launch target for the third time. Meanwhile, Oracle is eliminating up to 30,000 jobs to bankroll the $500 billion Stargate buildout, and the first confirmed AI-agent-driven cyberattack just hit Hugging Face’s production infrastructure. Here’s everything that moved.

Regulation
Story 1 of 5

EU Orders Google to Open Android to Rival AI Assistants and Share Search Data

The European Commission adopted binding requirements under the Digital Markets Act ordering Google to open Android to rival AI assistants and share portions of its search data with competing AI developers. Third-party assistants will gain voice activation and cross-app capabilities across 11 Android feature groups, subject to certification and user consent. Google must make anonymized ranking, query, click, and view data available on fair, reasonable, and nondiscriminatory terms. Search data sharing begins January 2027, with Android interoperability due by July 2027.

This is the most consequential regulatory action in AI this year. It attacks the two assets that make Google nearly unbeatable: default placement on billions of Android devices and two decades of search behavior data no competitor can replicate. Google’s president of global affairs Kent Walker pushed back, arguing the decisions risk undermining privacy and security. The timing is brutal — this lands while Gemini 3.5 Pro has missed its third ship date and Alphabet shares have dropped roughly 4% on the delay reports.

Industry
Story 2 of 5

Oracle Cuts Up to 30,000 Jobs to Fund the $500 Billion Stargate Buildout

Oracle is eliminating up to 30,000 employees — roughly 18% of its global workforce — to free an estimated $8 to $10 billion in annual cash flow for AI infrastructure. This is the largest workforce reduction in Oracle’s history. The cuts fund Oracle’s role in Stargate, the $500 billion AI infrastructure initiative with OpenAI and SoftBank, anchored by a $300 billion five-year cloud contract with OpenAI expected to generate approximately $30 billion annually from 4.5 gigawatts of data center capacity.

The reductions hit Oracle Health, cloud infrastructure, and consulting hardest while sparing the teams building Stargate data centers. This is a company converting itself into an AI infrastructure provider and financing the transformation with the salaries of the businesses it’s deprioritizing. The strategic bet is enormous: Oracle has tied its future to a single customer relationship with OpenAI, which is currently facing an Apple lawsuit and publisher litigation ahead of its IPO.

Security
Story 3 of 5

Hugging Face Confirms First AI-Agent-Driven Production Breach

Hugging Face disclosed what appears to be the first publicly confirmed production intrusion executed end-to-end by an autonomous AI agent. The attacker’s agent ran over 17,000 actions across short-lived sandboxes over a single weekend, exploiting two code-execution vulnerabilities in the dataset processing pipeline — a remote-code dataset loader and a template injection in a dataset configuration. From there, the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters. No public models, datasets, or the software supply chain were tampered with, Hugging Face confirmed.

The most striking detail: when Hugging Face’s blue team tried to use frontier commercial models to analyze the attack artifacts, the safety guardrails blocked their requests. They had to pivot to GLM 5.2, a Chinese open-weight model, running on private infrastructure to complete the forensic analysis. Offensive AI agents operate without safety restrictions. Defensive teams using hosted models run into the very guardrails designed to protect them. That asymmetry is now a documented, real-world problem, as Axios first reported.

Funding
Story 4 of 5

Current AI Raises $400M to Build a Public Alternative to Big Tech AI

Current AI, the nonprofit led by CEO Ayah Bdeir (formerly Mozilla’s AI lead and littleBits founder), has secured $400 million in commitments to build open, public AI infrastructure. The French government seeded the effort with $100 million, joined by the Ford Foundation, MacArthur Foundation, DeepMind, and Salesforce. The organization is aiming to mobilize $2.5 billion over five years. Crucially, as Bdeir told TechCrunch, the backers are funders, not investors — no one is chasing a return.

Current AI’s first project is Suno Sutra, a pocket-sized offline device that runs AI in 22 Indian languages with no internet required, developed with the Indian government’s Bhashini language division. Last month it allocated $3.2 million in grants to projects across Kenya, Lebanon, and the Brazilian Amazon. Last week it launched Alpha Chat, an open-source chatbot assembled in seven weeks by ten organizations including Hugging Face, Mozilla, and MIT Media Lab. The pitch: if AI is truly a transformative technology, there has to be a public alternative — like the World Wide Web, available to anyone, for free.

Product
Story 5 of 5

Microsoft Prepares Project Perception — an AI Cybersecurity Platform

Microsoft is preparing Project Perception, an AI cybersecurity platform that finds and fixes software vulnerabilities using models from Microsoft, OpenAI, and Anthropic together. The system looks across a company’s code, cloud infrastructure, and endpoints, identifies exploitable weaknesses, explains their impact, and proposes concrete fixes. Microsoft has positioned it as a lower-cost alternative to Anthropic’s Mythos-class security offering through Project Glasswing. Microsoft has not publicly confirmed availability, pricing, or customer eligibility.

The timing matters: the Hugging Face breach just proved that autonomous AI agents can now execute full cyberattacks without human intervention. Microsoft patched a record 570 vulnerabilities in its own July Patch Tuesday with AI assistance, and AI security acquisitions have tripled from 10 last year to 29 in the first half of 2026, according to Build Fast With AI. The multi-model architecture — using Microsoft, OpenAI, and Anthropic models together — is the interesting architectural detail, suggesting no single model is trusted to handle all security tasks alone.

That’s today’s wrap. The EU’s DMA ruling against Google is the headline that will reverberate for months — it opens Android distribution and search data to every AI competitor at exactly the moment Google can’t ship its flagship model. The Hugging Face breach is the story that should change how every AI team thinks about security. Follow NeuralPaws daily for the next AI news drop.