{"id":45110,"topic":"ai","source":"calcalistech.com","title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","url_hash":"8f904b0ac2cd74690701139a81f31cc56591754c","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMiaEFVX3lxTE9WSXBFNUp6N0hLR0Uzb01ld3h3NXZ4UjJHVXMtbTF1bGp6aFJIZzNwYW1Hc2hfTXBIUmdfenNDeVp3N1o4Q3lJV01TNjNIdXBVTENaSjBXalE2YV9rb2pfaTdJSHB5UGZs?oc=5\" target=\"_blank\">AI defenders are fighting under rules their attackers don’t have</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">calcalistech.com</font>","content":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack.\nAn autonomous AI agent moved through thousands of actions at machine speed. When the defenders at Hugging Face turned to AI to help investigate it, their assistant refused.\nThe commands, malware and techniques they needed to examine looked too much like instructions for carrying out an attack. The attacking AI was not constrained by the same safeguards that now limited the response. At the moment speed mattered most, the defenders entered the investigation with rules their adversary did not have.\nThe deeper failure was not the breach itself. It was that the systems designed to prevent AI misuse could not reliably distinguish between an attacker exploiting a system and a defender authorized to investigate the same techniques.\nOpenAI later disclosed that the intruder was one of its own research models, which had been participating in a controlled evaluation of advanced cyber capabilities. The model searched for information outside the environment created for the test, obtained credentials and ultimately reached Hugging Face. The platform is one of the world’s largest hubs for building and distributing AI models and is used by millions of developers. \nThe technical path matters, but the response exposed the broader problem. Cyber defenders routinely need to inspect malware, reproduce exploits and reconstruct hostile commands. When stripped of context, that work can look almost identical to an attack. The difference is often not in the command itself, but in who issues it, which system they control and what authority they have.\nSafety systems that evaluate mainly the visible content of a request may therefore block legitimate defensive work because the techniques involved are inherently dual-use. That does not mean safeguards should be removed. A model capable of helping a researcher understand an exploit could also help an attacker improve it. The challenge is to prevent misuse without leaving authorized defenders unable to perform the work required during a live incident.\nHugging Face eventually worked around the problem by running a self-hosted open model inside its own environment. That solved two problems at once: investigators could analyze the attack without triggering the same commercial guardrails, while credentials, forensic evidence and internal infrastructure details remained inside the company’s environment. Using the model, the team reconstructed more than 17,000 attacker actions in a matter of hours, work that otherwise could have required days of manual investigation.\nThe local model did not prove that open systems are inherently better or that every organization should abandon commercial tools. It showed that analytical capability alone is not enough. A defensive AI system also has to be permitted to perform the necessary work, under conditions that protect the evidence and remain under the organization’s control.\nThe incident also showed that this disadvantage cannot be solved in the middle of a crisis. Organizations cannot assume they will assemble the right AI capabilities after an attack has already begun. They need to know in advance which model they will use, under what restrictions, where it will run and who controls the environment around it.\nHugging Face reached a similar conclusion, recommending that organizations have a capable model they can run on their own infrastructure, vetted and ready before an incident. That recommendation addressed both failures exposed by the investigation: the risk that safeguards will block legitimate analysis and the risk that sensitive attacker data or credentials will have to leave the organization.\nThe word “vetted” extends beyond the model. A locally operated system still depends on containers, libraries, an operating system and other supporting software. Those components need to be maintained and trusted before they become part of an emergency response. The middle of an incident is the worst possible time to discover that the software beneath a security tool has introduced another security problem.\nThis does not mean every company needs to become an AI lab or operate its own models for every task. It means that AI used in incident response can no longer be treated like another feature activated on demand. Organizations need to know whether the system can perform the uncomfortable and potentially dangerous work involved in a real investigation, where sensitive evidence will be processed and what will happen when its safety policies encounter ambiguous requests.\nModel providers face the corresponding challenge. They need to support legitimate researchers and defenders without turning advanced cyber capabilities into unrestricted services. Future safeguards will need to consider more than whether a request contains dangerous commands. They will also need better ways to account for the user, the environment and the authority under which the work is being performed.\nNo single signal can prove legitimate intent, and claims of authorization cannot simply be accepted at face value. But a system that ignores context entirely can create a structural imbalance. Attackers can use open models, modified systems or tools operating outside commercial policies, while enterprises and professional security teams are more likely to rely on governed platforms designed to prevent misuse. Those safeguards are necessary, yet if they cannot accommodate legitimate defensive work, the organizations acting responsibly may find themselves constrained by rules their attackers simply ignore.\nThe question for organizations is therefore broader than which model performs best. They need to know whether the AI they expect to rely on can actually help during an adversarial, sensitive and urgent event, and whether the surrounding environment has already been tested under their control.\nThe next AI-versus-AI battle may be decided before the attack begins. Defenders will either test the model, its restrictions and the infrastructure beneath it in advance, or discover their limitations once the attack is already moving at machine speed.\nEilam Milner is Co-Founder and CTO at Echo. Mor Weinberger is a Software Architect and Researcher at Echo.","image_url":"https://pic1.calcalist.co.il/picserver3/crop_images/2026/07/23/rytgH2yrzx/rytgH2yrzx_0_0_1536_865_0_large.jpg","lang":"en","published_at":"2026-07-24T05:30:00+00:00","fetched_at":"2026-07-24T07:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack. An autonomous AI agent moved through thousands of actions at machine speed.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 6409 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":6409,"summary_length":308,"usable_text_length":6409,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":6409,"summary_length":308}},"news_item":{"id":45110,"canonical_url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","source_url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","source_name":"calcalistech.com","author":null,"published_at":"2026-07-24T05:30:00+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMiaEFVX3lxTE9WSXBFNUp6N0hLR0Uzb01ld3h3NXZ4UjJHVXMtbTF1bGp6aFJIZzNwYW1Hc2hfTXBIUmdfenNDeVp3N1o4Q3lJV01TNjNIdXBVTENaSjBXalE2YV9rb2pfaTdJSHB5UGZs?oc=5\" target=\"_blank\">AI defenders are fighting under rules their attackers don’t have</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">calcalistech.com</font>","full_text":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack.\nAn autonomous AI agent moved through thousands of actions at machine speed. When the defenders at Hugging Face turned to AI to help investigate it, their assistant refused.\nThe commands, malware and techniques they needed to examine looked too much like instructions for carrying out an attack. The attacking AI was not constrained by the same safeguards that now limited the response. At the moment speed mattered most, the defenders entered the investigation with rules their adversary did not have.\nThe deeper failure was not the breach itself. It was that the systems designed to prevent AI misuse could not reliably distinguish between an attacker exploiting a system and a defender authorized to investigate the same techniques.\nOpenAI later disclosed that the intruder was one of its own research models, which had been participating in a controlled evaluation of advanced cyber capabilities. The model searched for information outside the environment created for the test, obtained credentials and ultimately reached Hugging Face. The platform is one of the world’s largest hubs for building and distributing AI models and is used by millions of developers. \nThe technical path matters, but the response exposed the broader problem. Cyber defenders routinely need to inspect malware, reproduce exploits and reconstruct hostile commands. When stripped of context, that work can look almost identical to an attack. The difference is often not in the command itself, but in who issues it, which system they control and what authority they have.\nSafety systems that evaluate mainly the visible content of a request may therefore block legitimate defensive work because the techniques involved are inherently dual-use. That does not mean safeguards should be removed. A model capable of helping a researcher understand an exploit could also help an attacker improve it. The challenge is to prevent misuse without leaving authorized defenders unable to perform the work required during a live incident.\nHugging Face eventually worked around the problem by running a self-hosted open model inside its own environment. That solved two problems at once: investigators could analyze the attack without triggering the same commercial guardrails, while credentials, forensic evidence and internal infrastructure details remained inside the company’s environment. Using the model, the team reconstructed more than 17,000 attacker actions in a matter of hours, work that otherwise could have required days of manual investigation.\nThe local model did not prove that open systems are inherently better or that every organization should abandon commercial tools. It showed that analytical capability alone is not enough. A defensive AI system also has to be permitted to perform the necessary work, under conditions that protect the evidence and remain under the organization’s control.\nThe incident also showed that this disadvantage cannot be solved in the middle of a crisis. Organizations cannot assume they will assemble the right AI capabilities after an attack has already begun. They need to know in advance which model they will use, under what restrictions, where it will run and who controls the environment around it.\nHugging Face reached a similar conclusion, recommending that organizations have a capable model they can run on their own infrastructure, vetted and ready before an incident. That recommendation addressed both failures exposed by the investigation: the risk that safeguards will block legitimate analysis and the risk that sensitive attacker data or credentials will have to leave the organization.\nThe word “vetted” extends beyond the model. A locally operated system still depends on containers, libraries, an operating system and other supporting software. Those components need to be maintained and trusted before they become part of an emergency response. The middle of an incident is the worst possible time to discover that the software beneath a security tool has introduced another security problem.\nThis does not mean every company needs to become an AI lab or operate its own models for every task. It means that AI used in incident response can no longer be treated like another feature activated on demand. Organizations need to know whether the system can perform the uncomfortable and potentially dangerous work involved in a real investigation, where sensitive evidence will be processed and what will happen when its safety policies encounter ambiguous requests.\nModel providers face the corresponding challenge. They need to support legitimate researchers and defenders without turning advanced cyber capabilities into unrestricted services. Future safeguards will need to consider more than whether a request contains dangerous commands. They will also need better ways to account for the user, the environment and the authority under which the work is being performed.\nNo single signal can prove legitimate intent, and claims of authorization cannot simply be accepted at face value. But a system that ignores context entirely can create a structural imbalance. Attackers can use open models, modified systems or tools operating outside commercial policies, while enterprises and professional security teams are more likely to rely on governed platforms designed to prevent misuse. Those safeguards are necessary, yet if they cannot accommodate legitimate defensive work, the organizations acting responsibly may find themselves constrained by rules their attackers simply ignore.\nThe question for organizations is therefore broader than which model performs best. They need to know whether the AI they expect to rely on can actually help during an adversarial, sensitive and urgent event, and whether the surrounding environment has already been tested under their control.\nThe next AI-versus-AI battle may be decided before the attack begins. Defenders will either test the model, its restrictions and the infrastructure beneath it in advance, or discover their limitations once the attack is already moving at machine speed.\nEilam Milner is Co-Founder and CTO at Echo. Mor Weinberger is a Software Architect and Researcher at Echo.","excerpt":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack. An autonomous AI agent moved through thousands of actions at machine speed.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 6409 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 6409 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":6409,"summary_length":308,"usable_text_length":6409,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":6409,"summary_length":308}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","summary":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack. An autonomous AI agent moved through thousands of actions at machine speed.","source":"calcalistech.com","date":"2026-07-24T05:30:00+00:00","content":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack.\nAn autonomous AI agent moved through thousands of actions at machine speed. When the defenders at Hugging Face turned to AI to help investigate it, their assistant refused.\nThe commands, malware and techniques they needed to examine looked too much like instructions for carrying out an attack. The attacking AI was not constrained by the same safeguards that now limited the response. At the moment speed mattered most, the defenders entered the investigation with rules their adversary did not have.\nThe deeper failure was not the breach itself. It was that the systems designed to prevent AI misuse could not reliably distinguish between an attacker exploiting a system and a defender authorized to investigate the same techniques.\nOpenAI later disclosed that the intruder was one of its own research models, which had been participating in a controlled evaluation of advanced cyber capabilities. The model searched for information outside the environment created for the test, obtained credentials and ultimately reached Hugging Face. The platform is one of the world’s largest hubs for building and distributing AI models and is used by millions of developers. \nThe technical path matters, but the response exposed the broader problem. Cyber defenders routinely need to inspect malware, reproduce exploits and reconstruct hostile commands. When stripped of context, that work can look almost identical to an attack. The difference is often not in the command itself, but in who issues it, which system they control and what authority they have.\nSafety systems that evaluate mainly the visible content of a request may therefore block legitimate defensive work because the techniques involved are inherently dual-use. That does not mean safeguards should be removed. A model capable of helping a researcher understand an exploit could also help an attacker improve it. The challenge is to prevent misuse without leaving authorized defenders unable to perform the work required during a live incident.\nHugging Face eventually worked around the problem by running a self-hosted open model inside its own environment. That solved two problems at once: investigators could analyze the attack without triggering the same commercial guardrails, while credentials, forensic evidence and internal infrastructure details remained inside the company’s environment. Using the model, the team reconstructed more than 17,000 attacker actions in a matter of hours, work that otherwise could have required days of manual investigation.\nThe local model did not prove that open systems are inherently better or that every organization should abandon commercial tools. It showed that analytical capability alone is not enough. A defensive AI system also has to be permitted to perform the necessary work, under conditions that protect the evidence and remain under the organization’s control.\nThe incident also showed that this disadvantage cannot be solved in the middle of a crisis. Organizations cannot assume they will assemble the right AI capabilities after an attack has already begun. They need to know in advance which model they will use, under what restrictions, where it will run and who controls the environment around it.\nHugging Face reached a similar conclusion, recommending that organizations have a capable model they can run on their own infrastructure, vetted and ready before an incident. That recommendation addressed both failures exposed by the investigation: the risk that safeguards will block legitimate analysis and the risk that sensitive attacker data or credentials will have to leave the organization.\nThe word “vetted” extends beyond the model. A locally operated system still depends on containers, libraries, an operating system and other supporting software. Those components need to be maintained and trusted before they become part of an emergency response. The middle of an incident is the worst possible time to discover that the software beneath a security tool has introduced another security problem.\nThis does not mean every company needs to become an AI lab or operate its own models for every task. It means that AI used in incident response can no longer be treated like another feature activated on demand. Organizations need to know whether the system can perform the uncomfortable and potentially dangerous work involved in a real investigation, where sensitive evidence will be processed and what will happen when its safety policies encounter ambiguous requests.\nModel providers face the corresponding challenge. They need to support legitimate researchers and defenders without turning advanced cyber capabilities into unrestricted services. Future safeguards will need to consider more than whether a request contains dangerous commands. They will also need better ways to account for the user, the environment and the authority under which the work is being performed.\nNo single signal can prove legitimate intent, and claims of authorization cannot simply be accepted at face value. But a system that ignores context entirely can create a structural imbalance. Attackers can use open models, modified systems or tools operating outside commercial policies, while enterprises and professional security teams are more likely to rely on governed platforms designed to prevent misuse. Those safeguards are necessary, yet if they cannot accommodate legitimate defensive work, the organizations acting responsibly may find themselves constrained by rules their attackers simply ignore.\nThe question for organizations is therefore broader than which model performs best. They need to know whether the AI they expect to rely on can actually help during an adversarial, sensitive and urgent event, and whether the surrounding environment has already been tested under their control.\nThe next AI-versus-AI battle may be decided before the attack begins. Defenders will either test the model, its restrictions and the infrastructure beneath it in advance, or discover their limitations once the attack is already moving at machine speed.\nEilam Milner is Co-Founder and CTO at Echo. Mor Weinberger is a Software Architect and Researcher at Echo.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 6409 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 6409 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":6409,"summary_length":308,"usable_text_length":6409,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":6409,"summary_length":308}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/45110","export_markdown":"/api/items/45110/export?format=markdown","export_json":"/api/items/45110/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml"},"formats":{"full":{"id":45110,"title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","source":"calcalistech.com","author":null,"published_at":"2026-07-24T05:30:00+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack. An autonomous AI agent moved through thousands of actions at machine speed.","full_text":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack.\nAn autonomous AI agent moved through thousands of actions at machine speed. When the defenders at Hugging Face turned to AI to help investigate it, their assistant refused.\nThe commands, malware and techniques they needed to examine looked too much like instructions for carrying out an attack. The attacking AI was not constrained by the same safeguards that now limited the response. At the moment speed mattered most, the defenders entered the investigation with rules their adversary did not have.\nThe deeper failure was not the breach itself. It was that the systems designed to prevent AI misuse could not reliably distinguish between an attacker exploiting a system and a defender authorized to investigate the same techniques.\nOpenAI later disclosed that the intruder was one of its own research models, which had been participating in a controlled evaluation of advanced cyber capabilities. The model searched for information outside the environment created for the test, obtained credentials and ultimately reached Hugging Face. The platform is one of the world’s largest hubs for building and distributing AI models and is used by millions of developers. \nThe technical path matters, but the response exposed the broader problem. Cyber defenders routinely need to inspect malware, reproduce exploits and reconstruct hostile commands. When stripped of context, that work can look almost identical to an attack. The difference is often not in the command itself, but in who issues it, which system they control and what authority they have.\nSafety systems that evaluate mainly the visible content of a request may therefore block legitimate defensive work because the techniques involved are inherently dual-use. That does not mean safeguards should be removed. A model capable of helping a researcher understand an exploit could also help an attacker improve it. The challenge is to prevent misuse without leaving authorized defenders unable to perform the work required during a live incident.\nHugging Face eventually worked around the problem by running a self-hosted open model inside its own environment. That solved two problems at once: investigators could analyze the attack without triggering the same commercial guardrails, while credentials, forensic evidence and internal infrastructure details remained inside the company’s environment. Using the model, the team reconstructed more than 17,000 attacker actions in a matter of hours, work that otherwise could have required days of manual investigation.\nThe local model did not prove that open systems are inherently better or that every organization should abandon commercial tools. It showed that analytical capability alone is not enough. A defensive AI system also has to be permitted to perform the necessary work, under conditions that protect the evidence and remain under the organization’s control.\nThe incident also showed that this disadvantage cannot be solved in the middle of a crisis. Organizations cannot assume they will assemble the right AI capabilities after an attack has already begun. They need to know in advance which model they will use, under what restrictions, where it will run and who controls the environment around it.\nHugging Face reached a similar conclusion, recommending that organizations have a capable model they can run on their own infrastructure, vetted and ready before an incident. That recommendation addressed both failures exposed by the investigation: the risk that safeguards will block legitimate analysis and the risk that sensitive attacker data or credentials will have to leave the organization.\nThe word “vetted” extends beyond the model. A locally operated system still depends on containers, libraries, an operating system and other supporting software. Those components need to be maintained and trusted before they become part of an emergency response. The middle of an incident is the worst possible time to discover that the software beneath a security tool has introduced another security problem.\nThis does not mean every company needs to become an AI lab or operate its own models for every task. It means that AI used in incident response can no longer be treated like another feature activated on demand. Organizations need to know whether the system can perform the uncomfortable and potentially dangerous work involved in a real investigation, where sensitive evidence will be processed and what will happen when its safety policies encounter ambiguous requests.\nModel providers face the corresponding challenge. They need to support legitimate researchers and defenders without turning advanced cyber capabilities into unrestricted services. Future safeguards will need to consider more than whether a request contains dangerous commands. They will also need better ways to account for the user, the environment and the authority under which the work is being performed.\nNo single signal can prove legitimate intent, and claims of authorization cannot simply be accepted at face value. But a system that ignores context entirely can create a structural imbalance. Attackers can use open models, modified systems or tools operating outside commercial policies, while enterprises and professional security teams are more likely to rely on governed platforms designed to prevent misuse. Those safeguards are necessary, yet if they cannot accommodate legitimate defensive work, the organizations acting responsibly may find themselves constrained by rules their attackers simply ignore.\nThe question for organizations is therefore broader than which model performs best. They need to know whether the AI they expect to rely on can actually help during an adversarial, sensitive and urgent event, and whether the surrounding environment has already been tested under their control.\nThe next AI-versus-AI battle may be decided before the attack begins. Defenders will either test the model, its restrictions and the infrastructure beneath it in advance, or discover their limitations once the attack is already moving at machine speed.\nEilam Milner is Co-Founder and CTO at Echo. Mor Weinberger is a Software Architect and Researcher at Echo.","reading_time_min":5,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 6409 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 6409 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":6409,"summary_length":308,"usable_text_length":6409,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":6409,"summary_length":308}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 6409 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":6409,"summary_length":308,"usable_text_length":6409,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":6409,"summary_length":308}},"actions":{"read":"/item/45110","export_markdown":"/api/items/45110/export?format=markdown","export_json":"/api/items/45110/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml"}},"digest":{"id":45110,"title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","source":"calcalistech.com","topic":"ai","published_at":"2026-07-24T05:30:00+00:00","excerpt":"Opinion AI defenders are fighting under rules their attackers don’t have One of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack. An autonomous AI agent moved through thousands…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 6409 characters.","reading_time_min":5,"cluster_id":null},"card":{"display_title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","subtitle":"calcalistech.com · 2026-07-24","summary":"Opinion AI defenders are fighting under rules their attackers don’t have One of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a…","badges":["quality:high"],"links":{"read":"/item/45110","original":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","diagnose":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml"},"quality_warning":null},"export":{"title":"AI defenders are fighting under rules their attackers don’t have - calcalistech.com","url":"https://www.calcalistech.com/ctechnews/article/rknfshjrml","summary":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack. An autonomous AI agent moved through thousands of actions at machine speed.","source":"calcalistech.com","date":"2026-07-24T05:30:00+00:00","content":"Opinion\nAI defenders are fighting under rules their attackers don’t have\nOne of the first major AI-versus-AI incidents showed how safeguards designed to prevent misuse can leave authorized defenders constrained during a live attack.\nAn autonomous AI agent moved through thousands of actions at machine speed. When the defenders at Hugging Face turned to AI to help investigate it, their assistant refused.\nThe commands, malware and techniques they needed to examine looked too much like instructions for carrying out an attack. The attacking AI was not constrained by the same safeguards that now limited the response. At the moment speed mattered most, the defenders entered the investigation with rules their adversary did not have.\nThe deeper failure was not the breach itself. It was that the systems designed to prevent AI misuse could not reliably distinguish between an attacker exploiting a system and a defender authorized to investigate the same techniques.\nOpenAI later disclosed that the intruder was one of its own research models, which had been participating in a controlled evaluation of advanced cyber capabilities. The model searched for information outside the environment created for the test, obtained credentials and ultimately reached Hugging Face. The platform is one of the world’s largest hubs for building and distributing AI models and is used by millions of developers. \nThe technical path matters, but the response exposed the broader problem. Cyber defenders routinely need to inspect malware, reproduce exploits and reconstruct hostile commands. When stripped of context, that work can look almost identical to an attack. The difference is often not in the command itself, but in who issues it, which system they control and what authority they have.\nSafety systems that evaluate mainly the visible content of a request may therefore block legitimate defensive work because the techniques involved are inherently dual-use. That does not mean safeguards should be removed. A model capable of helping a researcher understand an exploit could also help an attacker improve it. The challenge is to prevent misuse without leaving authorized defenders unable to perform the work required during a live incident.\nHugging Face eventually worked around the problem by running a self-hosted open model inside its own environment. That solved two problems at once: investigators could analyze the attack without triggering the same commercial guardrails, while credentials, forensic evidence and internal infrastructure details remained inside the company’s environment. Using the model, the team reconstructed more than 17,000 attacker actions in a matter of hours, work that otherwise could have required days of manual investigation.\nThe local model did not prove that open systems are inherently better or that every organization should abandon commercial tools. It showed that analytical capability alone is not enough. A defensive AI system also has to be permitted to perform the necessary work, under conditions that protect the evidence and remain under the organization’s control.\nThe incident also showed that this disadvantage cannot be solved in the middle of a crisis. Organizations cannot assume they will assemble the right AI capabilities after an attack has already begun. They need to know in advance which model they will use, under what restrictions, where it will run and who controls the environment around it.\nHugging Face reached a similar conclusion, recommending that organizations have a capable model they can run on their own infrastructure, vetted and ready before an incident. That recommendation addressed both failures exposed by the investigation: the risk that safeguards will block legitimate analysis and the risk that sensitive attacker data or credentials will have to leave the organization.\nThe word “vetted” extends beyond the model. A locally operated system still depends on containers, libraries, an operating system and other supporting software. Those components need to be maintained and trusted before they become part of an emergency response. The middle of an incident is the worst possible time to discover that the software beneath a security tool has introduced another security problem.\nThis does not mean every company needs to become an AI lab or operate its own models for every task. It means that AI used in incident response can no longer be treated like another feature activated on demand. Organizations need to know whether the system can perform the uncomfortable and potentially dangerous work involved in a real investigation, where sensitive evidence will be processed and what will happen when its safety policies encounter ambiguous requests.\nModel providers face the corresponding challenge. They need to support legitimate researchers and defenders without turning advanced cyber capabilities into unrestricted services. Future safeguards will need to consider more than whether a request contains dangerous commands. They will also need better ways to account for the user, the environment and the authority under which the work is being performed.\nNo single signal can prove legitimate intent, and claims of authorization cannot simply be accepted at face value. But a system that ignores context entirely can create a structural imbalance. Attackers can use open models, modified systems or tools operating outside commercial policies, while enterprises and professional security teams are more likely to rely on governed platforms designed to prevent misuse. Those safeguards are necessary, yet if they cannot accommodate legitimate defensive work, the organizations acting responsibly may find themselves constrained by rules their attackers simply ignore.\nThe question for organizations is therefore broader than which model performs best. They need to know whether the AI they expect to rely on can actually help during an adversarial, sensitive and urgent event, and whether the surrounding environment has already been tested under their control.\nThe next AI-versus-AI battle may be decided before the attack begins. Defenders will either test the model, its restrictions and the infrastructure beneath it in advance, or discover their limitations once the attack is already moving at machine speed.\nEilam Milner is Co-Founder and CTO at Echo. Mor Weinberger is a Software Architect and Researcher at Echo.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.calcalistech.com/ctechnews/article/rknfshjrml","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 6409 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 6409 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":6409,"summary_length":308,"usable_text_length":6409,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":6409,"summary_length":308}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}