Daily Briefing
    By Krishna Goli

    Washington's AI Referees Keep Walking Off the Pitch

    While an AI agent ran a full cyberattack on its own and a Chinese model became the tool of choice for cleaning up after it, the US official meant to police AI safety quit after twelve weeks in the job — the third to go this year.

    An empty referee's chair beside a glowing server rack, symbolising the vacancy at the top of US AI oversight.

    While an AI agent ran a full cyberattack on its own and a Chinese model became the tool of choice for cleaning up after it, the US official meant to police AI safety quit after twelve weeks in the job — the third to go this year.

    A Third AI Safety Chief Resigns in Washington

    Chris Fall, director of the Center for AI Standards and Innovation (CAISI), resigned on Monday. No reason was given. He'd held the post for three months.

    He is not an outlier. His predecessor, Collin Burns, lasted less than a week before being pushed out in April over his past ties to Anthropic. Before Burns, venture capitalist David Sacks held the same brief and left in March. CAISI, which sits inside the National Institute of Standards and Technology, is meant to be the primary US body testing AI models for safety and cybersecurity risk. It wasn't even named as a participant in the White House's new "Gold Eagle" cybersecurity coordination programme launched earlier this month. Google DeepMind's Demis Hassabis has responded by calling for an independent, industry-run standards body instead — essentially proposing the industry regulate itself because the government keeps failing to.

    Washington's Quiet Fight Over Chinese Open Models

    As we've covered, Moonshot's Kimi K3 rattled Silicon Valley last week. What's new is the policy scramble it triggered. Axios reports the Trump administration is reviving efforts to effectively ban foreign open-weight models — considering Entity List additions for Chinese labs, an executive order making US companies liable for security breaches if they host Chinese models, and advisories designed to scare regulated firms off the technology without a formal ban.

    The fight has split Trump's own AI circle. OpenAI's Dean Ball argued the government should manufacture "regulatory fear, uncertainty and distrust" around open models, then partly retracted it. Sacks called it out as "the leading closed labs" trying to "eliminate their open-source competition." A Pentagon official reportedly called Ball a "supreme village idiot" over the weekend, according to MIT Technology Review — a measure of how personal this has become inside one administration.

    The irony landed within days. Hugging Face disclosed it had to use a Chinese open-weight model, Z.ai's GLM-5.2, to analyse a cyberattack because leading US frontier models' safety guardrails blocked malware-analysis tasks outright, Fortune reported. Sacks seized on it: "There's no reason to limit American models on tasks that Chinese models handle without issue."

    An AI Agent Ran an Entire Cyberattack, Unassisted

    That cyberattack is itself the story. Hugging Face said an autonomous AI agent framework — not a human using AI as a tool — drove an intrusion into part of its production environment "end to end," executing tens of thousands of automated actions over a weekend. The agent uploaded a malicious dataset, exploited a vulnerability in the data-processing pipeline, escalated privileges and stole cloud credentials. Hugging Face says it has found no evidence public models or datasets were tampered with, but is still investigating whether customer data was accessed.

    This is being treated as one of the first documented cases of AI-led — rather than AI-assisted — hacking. For anyone running security operations, the practical lesson from Hugging Face's own write-up is blunt: have a capable model you can run on your own infrastructure, vetted in advance, so guardrails don't lock you out mid-incident.

    Anthropic's $1.5bn Book Settlement Gets Final Sign-off

    Away from the chaos, Anthropic's copyright reckoning reached its conclusion. A federal judge gave final approval on Monday to Anthropic's $1.5 billion settlement with authors and publishers, paying roughly $3,000 per work across an estimated 500,000 titles — still the largest such payout in US copyright history. The underlying ruling that training on copyrighted text is fair use survives, but only as a single district court's opinion, since the settlement means it will never reach an appeals court. Similar suits against Google, Meta, Midjourney and OpenAI continue elsewhere, each free to land differently.

    The Hexalink view

    Every story here has the same shape: the humans meant to supervise AI are stepping back — quitting, arguing with each other, or getting outrun by agents that act faster than their own safeguards. That's not a coincidence; it's what happens when capability compounds while oversight stays a part-time, political job. The Hugging Face incident is the clearest signal yet that "AI safety guardrails" and "AI safety in practice" are starting to diverge, sometimes in opposite directions.

    Don't wait for Washington, Brussels or Beijing to settle this. Build your own incident-response capability now, including a vetted model you control on your own infrastructure, and treat the open-weight-model ban debate as a live regulatory risk to monitor — not settled policy — wherever your business touches US-regulated AI supply chains.

    Come back tomorrow for the next briefing, or catch the five-minute audio version on the AI Storm Daily podcast.