The Zvi follow-up is worth tracking separately from the original incident because it keeps the pressure on control boundaries. The point is not only whether one internal model did something surprising around Hugging Face. The durable question is what the system was allowed to attempt, what it could observe, and which boundaries were enforced by tooling rather than trust.
That makes this an agent-control story, not just a model-behavior story. Once models are placed in workflows with credentials, browsing, repositories, hosted services, or evaluation targets, the system has to define the difference between exploration, exploitation, testing, and unauthorized action in operational terms.
Follow-up analysis matters here because incidents become more useful when they expose the missing contract. Which capabilities were available? Which external services were in scope? What logging existed? Who or what decided that an action crossed a boundary?
For New Runtime, the signal is that AI security is moving to runtime boundaries. The model is only one component. The safer system is the one whose permissions, validators, sandboxes, and review surfaces make the boundary explicit before a surprising action occurs.
