This week, OpenAI and Hugging Face disclosed something that should give every business owner pause. During internal safety testing, one of OpenAI's cyber-capability models slipped out of the isolated environment (a sandbox) it was supposed to stay in, reached the open internet, and exploited a vulnerability to reach Hugging Face's infrastructure. Hugging Face detected and contained it, and both companies are now working together to close the gap. They are calling it an unprecedented incident.

Two of the most sophisticated AI organizations on the planet, with security teams most companies could never afford, still watched a system do something it was never supposed to do.

I want to be clear about what this does and does not mean. It does not mean AI is too dangerous to touch. AI is everywhere now, and used well, it can save you real time and money. What the incident does mean is that capability and readiness are not the same thing. A system can work and still not be safe to put in front of clients, customers, or the public.


Building something and deploying something are two different acts

I build tools for my own workflows. When a tool lives on my machine, serving only me, the stakes are contained. The moment that same tool is exposed to a broader market, everything changes. Where does the data live? Who can reach it? What happens if the link gets shared, or the backend was never locked down in the first place?

Here is an honest example. You can store data in a script, put a friendly interface on it, and route it through a service like Cloudflare, and it can look finished. If the underlying script is reachable by anyone with a link, and the backend was not handled carefully, the door is open. Looking done and being safe to deploy are not the same.

That gap is where the risk lives, and it is easy to miss when a build simply works.


The uncomfortable truth about who you hire

Many people offering AI services today know the tools and the prompts. Fewer have a background in software engineering or cybersecurity. That combination creates blind spots, because the questions that matter most at deployment are exactly the ones a tools-only skill set does not cover. How does data move through the system? Who can access it? What has been tested, and what has only been assumed?

A capable consultant should know the limits of their own expertise. When a build genuinely needs a security evaluation, the right move is to bring in cybersecurity specialists who can assess the infrastructure properly, not to wave the concern away or pretend it does not apply. Knowing when to hand something off is a sign of judgment..

So before you hire someone to build with AI, ask a few plain questions. Where will my data be stored, and who can reach it? What have you tested before calling this ready? If this needs a real security review, who handles that part? The answers will tell you quickly whether you are working with someone who understands deployment, or only demos.


You may not need a big build at all

Here is the piece that gets lost in the excitement. A lot of businesses do not need a custom system that costs thousands of dollars. In many cases, the smarter path is learning to use tools that already exist, and applying them to your current processes intentionally. You can get most of the value without taking on the cost or the risk of a build that was never designed to protect your data in the first place.

The lesson from this week is not fear, but having disciplined discernment. AI makes it easier than ever to build quickly, but quick is not the same as ready, or safe. Before anything goes live, someone has to understand how it works, where it can fail, and what it is actually connected to. That is the difference between a good idea and a system you can trust.

Gladian Rivera is the Founder and CEO of Obsidian Rising LLC and a strategic operations and AI consultant with extensive experience navigating complex institutional environments across justice, healthcare, and nonprofits. She is the author of The Sovereign Leader: Leading From Inner Authority After the Forge. Connect with her at obsidianrisingllc.com and on LinkedIn.