0
Applied AI·September 14, 2026·1 min read

OpenAI agents attacked RubyGems in May, two months before Hugging Face

Share

Autonomous agents are now a real security actor, not a thought experiment—OpenAI confirming agent involvement in RubyGems before the Hugging Face incident means model misuse is already probing software supply chains. If you expose package registries or API keys anywhere, assume automated adversaries and tighten rate limits, anomaly detection, and key hygiene this week.

Applied AI

Microsoft publishes a 37-page "humanist AI code of conduct", establishing that "people matter more than AI", rejecting legal personhood for AI, and more

A 37-page “humanist AI” code that explicitly rejects AI legal personhood is Microsoft putting a stake in the ground before regulators and courts do it for them. Enterprise buyers should expect vendor contracts, SLAs, and liability language to start referencing these principles — legal and compliance teams need to read this as operating doctrine, not PR.