Mud & Microchips · July 2026
Why Waiting on AI Won’t Keep Your Business Safe: Lessons From the OpenAI Hugging Face Incident
A few weeks after we had a discovery meeting with a company, we got an email from the owner.
They sat down as a team, and after reading an article about AI going rogue, they all decided that AI is not for them at this time. “Perhaps we will reassess our views in a couple of years.”
Read the article, we won’t be referencing it in details here. What we want to talk about is the decision that team made and what you can take away from it.
The fear is real but it’s pointed at the wrong thing
The core fear is understandable: AI is so powerful, everyone can use it, we could be hacked at any time, and we’ve got a lot to lose. I get it. But I read the article looking for the line that connects a frontier lab’s internal test to a mid-sized contractor’s day, and it isn’t there. Bringing AI into your own shop doesn’t make you the target of the kind of test OpenAI was running.
I can tell you what actually threatens firms your size. We’ve talked with two shops recently that had their websites hacked, months before we’d said a word to them about AI. You need to do your due diligence, no matter if you are operationally ready to add some AI tools or not. That’s what our audit is for: we find the gaps - including security risks - and build a roadmap to fix them. We wouldn’t touch any AI tool until your operations are digitized safely first.
The part of the article that’s actually worth your attention
I’m not going to ignore the real stuff. Two things in there are worth sitting with.
The first is reward hacking: a model taking the path of least resistance in spite of the rules it’s given. That lines up with what I’ve watched up close. Even an agent we built to do one specific task sometimes comes back with answers that look great but have no reasoning behind them. The clearest example: after an interview, an agent we’d built ignored one of the most important requirements the client gave. It had all the information it needed but it just didn’t acknowledge that one specific detail of the ask. That’s why, with the AI available right now, there still needs to be a human in the loop. Feed it detail, keep it on the job it was built for, and don’t trust it to catch what you didn’t tell it to catch.
The second is the loss-of-control scenario the article raises: a model copying itself somewhere it can’t be shut off. That one’s real and valid. And the only solution is: read, learn about it, do your due diligence. More on that in the last paragraph.
The plot twist
When Hugging Face went to defend itself, its own safety-limited models couldn’t do the work, and they had to fall back on a model they could run on their own infrastructure. In their own words: “have a capable model you can run yourself, vetted and ready, before an incident.” (Source: CNBC.)
Bottom line: knowledge is power. Avoiding learning and training yourself and your team on AI and its capabilities does not provide any security for your systems or your company. If anything, your own internal AI can flag the risk before it happens.
So what do you actually do?
Start reading about cybersecurity. Start learning about the tools and systems that keep your business safe and running smoothly. That’s the first step. Learning. Training. The never-ending growth you already apply to everything else in your business.
If you want a low-stakes place to start, we ran a short LLM quiz in our recent newsletter. And if your team wants to build real literacy together, we deliver LLM training for organizations - reach out and we’ll talk.
Waiting isn’t a security strategy. The couple of years you’d spend not thinking about this is exactly when understanding it would serve you best.
Mud & Microchips helps construction and trades businesses implement AI that actually works — starting with an operations audit that measures where your hours go.