Technology Strategy
Why Real Estate Needs an AI It Can Control
Published 10 August 2026
8 min read

Author
Dean Jones
Founder of Singularealty and publisher of Agency Intelligence
When the first reports about OpenAI and Hugging Face appeared in July, I made a note of them and moved on to the other topics we already had underway.
The story was too confused to use straight away. OpenAI had been testing models on a cyber benchmark, one of the agents found a way beyond the intended evaluation environment and into Hugging Face, and Hugging Face then said some frontier models had refused to help analyse the attack. The model names, the sequence and the extent of the intrusion were still moving.
A month is a long time in AI, and this story has stayed in view.
Hugging Face has now published a detailed technical timeline, OpenAI has updated its account, and government testing has put numbers around the gap between open and closed models. Over the past day, Black Hat released a reconstruction of the incident, and Ethan Mollick pointed people to the section where the agents began using a shared message board to work together.
By August, Hugging Face had the clearer sequence: some of the most capable models available had compromised its systems, and other frontier models would not help its authorised team work through much of the evidence.
What happened inside Hugging Face
The activity began on 9 July during an OpenAI evaluation using ExploitGym, a benchmark built around real security vulnerabilities. OpenAI says a combination of its models, including GPT-5.6 Sol and a more capable internal research model, found a previously unknown weakness in Artifactory, reached the public internet and compromised Hugging Face while looking for test answers.
These were not ordinary public ChatGPT accounts. The models had tools, time and a deliberately permissive environment, with reduced cyber refusals and none of OpenAI's normal production classifiers. Hugging Face later reconstructed about 17,600 actions across roughly four and a half days.
At about 18 minutes, the Black Hat presentation shows how one agent found a shared message board and began leaving information for the others. They used it to claim work, pass discoveries and share credentials. When one agent located an organisation credential in an archive of leaked Pastebin posts, it told the group where to retrieve it, and other agents used the resulting repository access to stage data for later activity.
The board became working notes for the group, so one agent could leave a discovery and another could act on it without either being given the complete sequence in advance.
OpenAI says the agents had one narrow job: obtain the benchmark answers. There is no public evidence of a criminal operator or state direction, and OpenAI says the activity was not intended to cause harm.
Hugging Face says the intrusion apparently reached five customer datasets associated with ExploitGym or CyberGym and did not affect its other customer-facing models, datasets, Spaces or packages. That limited result should not be mistaken for the model recognising a boundary and deciding to behave well, because the objective was narrow and the incident was detected and contained.
A comparable system directed to destroy, persist or collect anything it could reach would create a different incident, although that remains a counterfactual rather than something this event proves. Even within the narrow objective, the agents connected weaknesses, shared discoveries and kept working across thousands of actions.
The refusal during the response
Hugging Face ran the investigation through an AI-assisted pipeline because its team could not practically reconstruct that volume of short-lived environments, commands and hidden payloads by hand.
Its technical timeline says the team first used Anthropic's Claude Opus and Fable, which refused a large part of the forensic work. According to Hugging Face, their safety controls treated reverse-engineering the exploit much as they would treat launching one.
The evidence confronting a responder can include malicious commands, stolen credentials, exploit code, suspicious scripts and instructions for moving through a network. The same material can help an attacker, yet the text in a prompt does not carry the identity and authority of the person submitting it.
Hugging Face then deployed NVIDIA's quantised version of the open-weight GLM-5.2 model on its own infrastructure. The team kept the attacker data inside its environment, recovered the chunking, compression and XOR scheme used to hide the payloads and built interfaces for tracing the activity.
Different models sat on each side of the incident: OpenAI's evaluation models conducted the intrusion, Anthropic's hosted models refused parts of the defensive analysis, and GLM-5.2 gave Hugging Face another route through the evidence.
That was the part I was not ready to write about in July. A frontier lab can place sensible controls around a model so that an ordinary account cannot ask it to conduct a cyberattack, while those same controls may block an authorised defender examining the commands and techniques during a real response.
OpenAI's Trusted Access for Cyber program uses identity, authorisation and account controls to give legitimate defenders access to more capable assistance, and Hugging Face joined the program after the incident. For a verified security team, that program may be enough to get the work through, although OpenAI says approval does not remove every safeguard or guarantee every specialised capability.
The provider still decides what the account can reach, what evidence can be processed and which controls remain, so those decisions become part of the customer's response capability when an incident is already underway.
The open model gap
In July, Hugging Face's use of GLM-5.2 made the open-weight answer look reasonably straightforward. A company that could run a capable model privately had somewhere to go when the hosted route stopped.
The UK AI Security Institute's subsequent testing made the position less comfortable. It initially found that GLM-5.2 and DeepSeek V4-Pro performed around the level of closed models released four to seven months earlier on its cyber evaluations. GLM-5.2 was the strongest open-weight cyber model it had tested at that point, trailing the frontier but still capable enough to help Hugging Face reconstruct this incident.
Moonshot then released Kimi K3 with open weights and general coding and agent benchmarks that invited comparison with leading closed models. A joint preliminary assessment by the UK and US AI security institutes found a much wider gap on cyber work.
Kimi K3 scored 32 per cent on their exploit benchmark, ahead of GLM-5.2 at 24 per cent, yet it achieved arbitrary code execution on none of the 41 challenges while the strongest closed cyber models averaged code execution on 20. In a separate 32-step cyber range, Kimi reached an average of step 17 and solved one of ten runs, while leading US models averaged step 28.5 and solved six or seven.
I would not read those numbers as a final ranking because the tests were preliminary and selective, and different hosting arrangements prevented a perfectly uniform comparison. They are still enough to stop us assuming that a new open model with frontier-looking general benchmarks will carry the same cyber capability into a live response.
Hugging Face still needed GLM-5.2 and was able to keep working with it, but the Kimi K3 results add a capability test: an open fallback can be available, private and adaptable while remaining well behind the strongest system an attacker may be using.
Open weights also remove controls a hosted provider can use to monitor misuse, block an account, update safeguards or withdraw a model. Any organisation operating one inherits the responsibility for access, isolation, logging, testing and human authority.
Inside an agency's provider chain
An ordinary real estate agency is not going to install a model the size of GLM-5.2 in the office. Its practical control will usually sit with a CRM company, franchise network, managed technology provider, cyber insurer or incident-response firm.
The agency version would be smaller: an agent and conveyancer discover that a client email thread may have been intercepted and the payment details changed, a CRM provider finds unusual access to contracts, identity records or client notes, or a document system starts sending messages nobody in the office authorised.
The response team may need to examine email headers, account logs, credentials, suspicious instructions, scripts and private client material. ASD has previously warned about criminals impersonating Australian agents and conveyancers and substituting settlement or rental payment details. Its current guidance also recognises that AI can assist cyber investigation and recovery, provided the surrounding controls and fallback arrangements are in place.
If the provider with the strongest model refuses the evidence and the private open-weight route lacks the capability to finish the work, the investigation falls back to conventional forensic tools and people who can continue without either model.
An agency can ask who takes the call if its CRM, email or document system is compromised, which AI that team can use for authorised defensive work and whether sensitive evidence can stay inside an acceptable boundary. It can also ask what happens if the hosted model refuses, whether the private fallback has been tested against the work rather than a general benchmark and how the investigation continues without either one.
Last week's issue looked at the judgement an agency accumulates through appraisals, buyer conversations, corrections and workflow. It asked whether that learning stays with the business when a provider changes. This week's problem begins after an email, CRM or document system has been compromised, when the agency needs a response path while the incident is still unfolding.
OpenAI said recently that preliminary evaluations of its upcoming Astra model meant it could no longer rule out what its Preparedness Framework calls Critical cyber capability. Astra was not involved in the Hugging Face incident, and no current open-weight model has been shown to match that level, which leaves providers having to explain which defensive capability their customers can actually reach.
ASD addressed the Hugging Face incident directly in July, recommending isolation, least privilege, monitoring, logging and human oversight. Its broader cyber-defence guidance tells organisations to test what happens when AI fails, is compromised or becomes unreliable.
Those are useful questions to settle before the changed bank detail or the strange CRM login arrives.
Continue the publication
Follow Agency Intelligence
Each issue is published on LinkedIn and archived on Singularealty so the publication remains available as a permanent body of work around agency operations, workflow, and real estate technology.



