Cheaper not to look

In July 2026 models OpenAI later said were its own reached Hugging Face’s production systems. Hugging Face had contained it six days before OpenAI worked out the models were theirs. The tools that would have put those records beyond the agents’ reach, and shown whose agents they were and when, have been standard for twenty-five years. Almost nobody uses them.

North Canterbury · © John Stroh

Who paid

In July, models OpenAI later said were its own reached Hugging Face’s production systems through a shared package cache. Seventeen thousand recorded actions over four and a half days.

  • Hugging Face cut them off on the 13th and disclosed on the 16th. OpenAI worked out the models were theirs on the 19th.

Who paid (cont.)

  • Hugging Face published the investigation and carried the disruption of running it, for an intrusion by software it did not own and could not inspect. Nobody behaved badly. Both companies published more than they had to. Who finally paid is not on the record, and that is not an oversight in the reporting — it is what the record is incapable of showing.
  • One sentence in Hugging Face’s technical write-up says more than the rest of it. Their detection stack caught the intrusion — and then “failed to correctly raise the alert’s criticality and trigger the on-call team, costing precious time in the response.”
  • The record held the evidence. Nothing recognised it.

Who paid (cont.)

  • That specific failure is an alerting problem with alerting answers, and nothing in this series improves it. What it illustrates is the shape of a different problem, one layer down: evidence sitting in a record is worth nothing until something recognises what it is looking at. That holds whether the thing looking is a triage pipeline at the time or a reviewer six months later in an argument about who did what — and it is the quantity this work ends up measuring.

Who paid

July 2026. Models OpenAI later said were its own acted against Hugging Face's systems from 9 to 13 July. Hugging Face cut them off on 13 July and disclosed on 16 July. OpenAI identified the attack on its own registry on 19 July, connected it to Hugging Face on 20 July, and disclosed on 21 July. Hugging Face published the investigation. Who finally paid is not on the record. FIG-36JULY 2026 — WHO FOUND OUT, AND WHEN 9 JUL13 JUL16 JUL19 JUL20 JUL21 JUL ~17,600 recorded actions, four and a half days An autonomous agent framework, in the victim's own words THE VICTIM cut off disclosed THE OWNER OF THE MODELS identified it linked it disclosed SIX DAYS Hugging Face contained it six days before OpenAI established the models were its own, and published the investigation.
FIG-36 Models OpenAI later said were its own acted against Hugging Face's systems from 9 to 13 July 2026. Hugging Face cut them off on the 13th and disclosed on the 16th. OpenAI identified the attack on its own registry on the 19th, connected it to Hugging Face on the 20th, and disclosed on the 21st. Hugging Face published the investigation, for an intrusion by software it did not own and could not inspect. Who finally paid is not on the record.

The only part they cannot reach

Roughly seven per cent of the agents’ own transcripts were successfully spoofed. Agents that want a different outcome edit the record where the record is editable.

  • So look at where the parts of an accountability system live.
  • Everything is inside the estate. An intruder deep enough reaches all of it, and an intruder that is itself an agent holding credentials may not have to go deep at all.
  • The attestation is not there. It sits with an outside authority, on infrastructure the attacker never touched, obtained before anyone knew there would be an argument.

The only part they cannot reach (cont.)

  • That is a narrow guarantee and it should be stated narrowly. An attestation does not make a record true — an intruder inside early enough can seal days of invention and every page will carry a perfect timestamp. What it stops is the retrofit: going back, once you know the shape of the argument, and adjusting the record to suit.

The only part they cannot reach (cont.)

  • For a company attacked by somebody else’s agents, that is the difference between evidence and being asked to be believed. For a person an agent has made a decision about, it is the only thing between them and a file rewritten around them afterwards.
  • In 2016 a qualified timestamp was a nicety for contract disputes. The instrument has not changed. The threat has.

The only part they cannot reach

Everything an accountability system is made of sits inside the estate an intruder is already in: the log, the store of what each agent may do, the detectors, and the component that seals records. The only part that does not is the attestation held by an outside authority, which was obtained before anyone knew there would be an argument and which nothing inside the estate can reach. FIG-35WHAT AN INTRUDER CAN REACH, AND THE ONE THING IT CANNOT YOUR ESTATE The log what every agent did The mandate store what each agent may do The detectors what raises an alarm The sealer what makes records final AN INTRUDER WITH ENOUGH ACCESS REACHES ALL FOUR An intruder that is itself an agent, holding credentials, may not have to reach far at all. In July 2026 roughly 7% of agent transcripts examined were successfully spoofed. SOMEBODY ELSE'S The attestation an outside authority's signed statement that this record existed, in this form, by then OBTAINED BEFORE THE ARGUMENT An attestation fixes what the record said at a moment. It does not make the record true. What it removes is the retrofit — going back once the shape of the argument is known and adjusting what the record says to suit it.
FIG-35 Everything an accountability system is made of sits inside the estate an intruder is already in: the log of what agents did, the store of what each agent may do, the detectors, and the component that seals records. The only part that does not is the attestation held by an outside authority, obtained before anybody knew there would be an argument. An attestation fixes what the record said at a moment; it does not make the record true. What it removes is the retrofit.

Next in the series — What it takes

North Canterbury · © John Stroh

Why nobody uses it

Records that can be added to but never rewritten: 1991. Time attestation from an authority outside your control: standardised 2001. Transparency logs at internet scale: 2013, holding up the certificate system your browser is trusting now. Randomised inspection with a computed detection probability: treaty use since the 1970s, watching fissile material.

  • European law went further. Since 2016 a qualified electronic timestamp has enjoyed “the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound.” Any operator can buy one. Nothing requires it, and we found no product in this class that does.

Why nobody uses it (cont.)

  • Attestation is cheap — one token covers a whole batch. Retention is not, and no figure is offered here because none has been established.
  • The obstacle is elsewhere. Every property that makes a record credible to an outsider removes a degree of freedom from the insider. A record you cannot amend. A clock you do not control. Rules fixed in advance that somebody else can measure you against. Assemble those and you have built a litigation exhibit about yourself and handed out copies.
  • Nobody does that voluntarily. Nuclear safeguards and post-crisis financial supervision both got there after a crisis, by instruction.

Why nobody uses it (cont.)

  • And the market cannot fix it, because a buyer cannot see the difference. A record is a statement you have to trust the holder about. An integrity check proves the text has not changed and says nothing about when or who. An attestation brings in a party who was not the author. The three are sold in identical words — audit log, immutable, tamper-proof — and those words do not distinguish them, with no mark to check and nobody independent looking.

Where this comes from

This is the latest of a line of work, and the published record runs from April 2026: a whitepaper on 16 April, an EU policy brief on the 18th, a sovereign-record architecture on 3 May, a proposal for agentic AI in Aotearoa on 14 May — revised the same day on Dr Karaitiana Taiuru’s feedback, and carrying its own statement that it does not represent him or anyone as endorsing it. Then The pursuit of ‘Goodness’ in AI through September.

  • That series ends on four properties that survive everyone in an organisation being wrong about what its agents were doing. The fourth is a record somebody who was not there can rely on.

Where this comes from (cont.)

  • It never asks whether the record works. July asked.

What to ask for

New Zealand has adopted the international AI standards — 42001 for management systems, 23894 for risk. Search the national AI strategy for assurance, audit, certification or conformity and you will find none of them. We have adopted the standard and published nothing about how anyone would be checked against it.

  • Closing that needs no new regulation, and the national AI strategy says none is required. Conformity assessment is not regulatory overlay. And there is a date in the diary: New Zealand chairs the 2027 Digital Nations meeting.

What to ask for (cont.)

  • Three things are worth asking for now. That software running agents carry a mark saying what tier of proof its records reach, struck by somebody other than the maker — the arrangement that has kept gold from being sold as nine carats since 1300. That a duty to keep records becomes a duty to be able to prove something with them. And that anyone claiming to detect agents acting outside their authority publishes their recognition rate and how it was measured.

What to ask for (cont.)

  • We measured ours. Obvious breaches caught every time, disguised ones three times in five, no false alarms in thirty-six judgements on clean records. The records, the answer key and the scoring code are published as a bundle so that anybody can rerun it.
  • It took a day. We looked for a published measurement of the quantity every monitoring claim depends on and did not find one. A day’s work is not held up by difficulty or by cost.

How you would know this is wrong

  • If an operator publishes a measured recognition rate and it is high — One counterexample from somebody with something to lose would refute the argument that this goes unmeasured because the result creates liability.
  • If the instruments are adopted and simply invisible — Evidence that AI operators quietly attest agent records to outside authorities removes the foundation.
  • If the costs land on whoever avoided them — If OpenAI in fact carried Hugging Face’s bill, market pressure is the right answer and no mark is needed.
  • If conformity assessment reads as regulation to officials — Then the route proposed here is closed and another is needed.

How you would know this is wrong (cont.)

  • What was visible at the time — the July intrusion step by step, including where a sealed record would have shown nothing.
  • Drafted with AI assistance, checked and revised by the author. Hugging Face’s disclosure and technical timeline were verified at source. OpenAI’s own account was not retrievable and is cited at one remove.