Venerdì scorso Tara Wheeler (AI’s hacking capabilities are severely underestimated, FU 28.8.26 p. 17) ha tra l’altro scritto: “Publicly available AI subscription models like Claude have
safeguards that mostly prevent requests to create exploits. But those safeguards do not exist when
someone runs open-weight models on their own hardware”. Mi domando se sia un argomento di marketing: io ho avuto il problema x ma l’ho risolto e posso risolverlo; i miei competitors non potranno mai risolverlo.

__________________________________________
Prof. Avv. Marco Ricolfi
C.so Galileo Ferraris, 43 - 10128 Torino
T (+39) 011.554.54.11
F (+39) 011.518.45.87
E
marco.ricolfi@weigmann.it
PEC marcoricolfi@pec.ordineavvocatitorino.it
www.weigmann.it
![]()
Member of The Parlex Group of European Lawyers EEIG with associated law firms in the main capitals of the European Union, U.S.A., Israel and Malaysia; web site: www.parlex.org
DISCLAIMER: Le informazioni contenute in questa comunicazione sono riservate e destinate esclusivamente alla/e persona/e o all'ente/i destinatario. È vietato a soggetti diversi dai destinatari di questa comunicazione qualsiasi uso, copia o diffusione delle
informazioni e dei dati in essa contenuti, sia ai sensi dell'art. 616 c.p. sia ai sensi del Regolamento (UE) 2016/679. Se questa comunicazione Vi è pervenuta per errore, Vi preghiamo di informarci chiamando il numero (+39) 011.554.54.11, ovvero di rispondere
a questa e-mail e successivamente, di cancellare dal Vostro sistema la e-mail ed ogni suo allegato.
DISCLAIMER: The information contained in the e-mail is confidential and intended only for the attention of the named individual(s) or organisation(s) to whom it is
addressed. If you are not the intended recipient be aware that any use, copying or distribution of the information contained herein is prohibited pursuant to Article 616 of the Italian Penal Code and (EU) Regulation 2016/679. If the communication has been
sent to you in error, please notify us by telephone on (+39) 011.554.54.11, or reply to the e-mail. Please then delete the e-mail and any attachments from your system.
Da: Daniela Tafani via nexa <nexa@server-nexa.polito.it>
Inviato: venerdì 4 settembre 2026 15:38
A: nexa@server-nexa.polito.it; Viola Negro <viola.negro@polito.it>
Oggetto: [nexa] R: Caso Hugging face
Buongiorno, io condivido la lettura dell'episodio data da Erik Salvaggio, in The System From Nowhere.
Si tratta, a voler essere benevoli, di un caso di incompetenza raccontato in modo fantascientifico per ragioni pubblicitarie:
"The system from nowhere" is a way of talking about AI systems that excludes its origin as a consciously, human-designed product. It treats AI as if it were a spontaneously emerging force.
It's a reflection of where an observer draws the system’s boundary when they look at it. It’s also a rhetorical magic trick that makes both AI companies, labor and the underlying material infrastructure disappear.
Recently, an OpenAI model "hacked" another AI company, Hugging Face. The headlines:
New York Times: “OpenAI says its models went rogue and attacked a digital library.”
Wired Magazine: “OpenAI models escaped containment and hacked Hugging Face.”
Washington Post: “OpenAI’s models went rogue and hacked another company.”
When we say “AI models went rogue,” we skip the entire story: the part where OpenAI manually removed the model's cybersecurity blocks.
We skip that OpenAI chose to test it on a machine with a live network connection.
If you see AI as a system from nowhere, you can make the claim that the model “went rogue,” and that it “broke containment,” both of which place agency and decision-making onto the model itself rather than the people who set the stage for that behavior.
When you expand the boundary of the system to include the people building and deploying it, the case becomes much less science fiction and more like incompetence.
OpenAI developers optimized an LLM specifically for cybersecurity and coding and then ran it without security guardrails.
So they trained a model to find exploits and then acted surprised that it found them.
Continua qui: <https://mail.cyberneticforests.com/the-system-from-nowhere/>
La ricostruzione di Salvaggio è confermata da Margaret Mitchell, di Hugging Face, pur con qualche antropomorfizzazione dovuta forse alla scelta di servirsi di una storia a fumetti:
<https://m-mitchell.com/HF-hack-cartoon/>
________________________________________
Da: Viola Negro via nexa <nexa@server-nexa.polito.it>
Inviato: giovedì 3 settembre 2026 12:56
A: nexa@server-nexa.polito.it
Oggetto: [nexa] Caso Hugging face
Buongiorno!
Mi sono imbattuta in questo<https://substack.com/inbox/post/213737931?utm_source=email&redirect=app-store-no-desktop&inbox=true&utm_campaign=email-read-in-app&triedRedirect=true>
articolo di Jordan Schneider su Chinatalk su substack sul caso Hugging face hack e open AI di cui c’è qui una breve descrizione:
https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-highlights.
La notizia è abbastanza diffusa ormai.
Che cosa ne pensate di questo fatto? È davvero così “sensazionale” come alcuni articoli riportano o uno dei tanti incidenti di percorso? Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati per diventare attori strategici di attacco/guerra
oppure questa lettura esagera il tutto?
Buon inizio settembre a tutte e tutti!
Viola Negro
Fellow
Nexa Center for Internet & Society
Politecnico di Torino - DAUIN
Via Pier Carlo Boggio, 65/A - 10138 Torino
web:
https://nexa.polito.it/
mail: viola.negro@polito.it
_______________________________________________
nexa mailing list -- nexa@server-nexa.polito.it
To change settings or unsubscribe please go to:
https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/
The general archive of the list is located at:
https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/
Permalink to this message:
https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/message/YOR5T3MX4HZY46625WPUMB5RBURX436G/