{"schema_version":"newruntime-agent-readable-v0.2","type":"raw_signal","stable_id":"signal:openai-hugging-face-incident-followup","id":"nr-7f814d23-openai-hf-followup","slug":"openai-hugging-face-incident-followup","title":"The OpenAI Hugging Face Follow-Up Is Really About Control Boundaries","description":"The Zvi follow-up on the OpenAI and Hugging Face incident keeps pointing back to evaluation boundaries, permissions, and agent control surfaces.","retrieval_nugget":"The Zvi follow-up on the OpenAI and Hugging Face incident keeps pointing back to evaluation boundaries, permissions, and agent control surfaces. As models are given richer work surfaces, incidents are less about one prompt and more about the control plane that defines what the system can attempt, observe, and change. Novelty is notable; verification is source-linked.","observed_at":"2026-07-29","record_date":"2026-07-29","date_kind":"observed_at","why_it_matters":"As models are given richer work surfaces, incidents are less about one prompt and more about the control plane that defines what the system can attempt, observe, and change.","novelty":"notable","verification_level":"source-linked","signal_type":"independent-analysis","evidence_kind":"independent-analysis","status":"published","source_platform":"newsletter","source_record_id":"7f814d23-openai-hf-followup","source_url":"https://thezvi.substack.com/p/more-on-an-internal-openai-model","topics":["ai-security","evals-benchmarks"],"entities":["OpenAI","Hugging Face","The Zvi","agent safety"],"related_patterns":["agent-security-moves-to-runtime-boundaries","verification-bandwidth-is-the-scarce-resource","agent-ready-software-exposes-capabilities"],"source_urls":["https://thezvi.substack.com/p/more-on-an-internal-openai-model"],"import_batch":"newsletter-7f814d23-9a63-4cfa-98a1-ef53e872d6e5","routes":{"html":"https://newruntime.com/signals/openai-hugging-face-incident-followup/","markdown":"https://newruntime.com/signals/openai-hugging-face-incident-followup.md","json":"https://newruntime.com/signals/openai-hugging-face-incident-followup.json"},"source_format":"editorial-inbox-sanitized-batch","next_reads":[{"type":"pattern","path":"/patterns/agent-security-moves-to-runtime-boundaries/","reason":"Pattern connected to this observed signal.","url":"https://newruntime.com/patterns/agent-security-moves-to-runtime-boundaries/","title":"Agent security moves to runtime boundaries","media_type":"text/html"},{"type":"pattern","path":"/patterns/verification-bandwidth-is-the-scarce-resource/","reason":"Pattern connected to this observed signal.","url":"https://newruntime.com/patterns/verification-bandwidth-is-the-scarce-resource/","title":"Verification bandwidth is the scarce engineering resource","media_type":"text/html"},{"type":"pattern","path":"/patterns/agent-ready-software-exposes-capabilities/","reason":"Pattern connected to this observed signal.","url":"https://newruntime.com/patterns/agent-ready-software-exposes-capabilities/","title":"Agent-ready software exposes capabilities","media_type":"text/html"},{"type":"topic","path":"/topics/ai-security/","reason":"Explore the ai security topic hub.","url":"https://newruntime.com/topics/ai-security/","title":"AI Security - New Runtime","media_type":"text/html"},{"type":"related_material","path":"/signals/mcp-oauth-authorization-boundary/","reason":"Shares ai security.","url":"https://newruntime.com/signals/mcp-oauth-authorization-boundary/","title":"MCP and OAuth Put Agent Authorization on the Critical Path","media_type":"text/html"}]}
