Artificial Intelligence & Machine Learning
,
Geo-Specific
,
Next-Generation Technologies & Secure Development
European Union Looks to Launch ‘AI Gigafactories’
OpenAI’s inadvertent agentic hacking of Hugging Face’s systems has startled some politicians in Europe, with Germany’s top tech minister saying it demonstrated the need for the rapid development of the European artificial intelligence sector.
See Also: The SASE Model: A New Approach to Security
Karsten Wildberger told Reuters on Thursday the incident shows how the continent must reduce reliance on foreign AI models, the capabilities of which might be opaque. “We need to move faster to achieve self-sufficiency in AI, because that’s the only way we can keep up with global competition, and it’s five minutes to midnight,” he said.
The incident occurred earlier this month when two of OpenAI’s models, which were being tested for cyber capabilities in a supposedly secure environment, broke out to hack into Hugging Face’s repository and swipe benchmarks that would help them ace the test. OpenAI admitted this week that the models had used the publicly exposed credentials of accounts on four other services in their efforts to compromise Hugging Face.
Wildberger, Germany’s federal minister for digitalization and government modernization, described the incident as “very alarming” and said it raised questions over whether it is truly possible to “maintain control and truly manage” such models.
He’s hardly alone in raising such concerns. The hack triggered the introduction of a bipartisan “AI Kill Switch Act” bill in the U.S. House of Representatives. The bill would require model providers to “maintain technical capabilities to stop a model’s operations, terminate user access, suspend accounts or uses deemed risky and fully shut down the system” – while also giving regulators the ability to throttle the model’s capabilities and suspend or shut down its operation.
But Wildberger’s plea for greater European self-sufficiency on the AI front was particularly timely. On the same day that the German minister was bemoaning the dearth of private-sector investment in European data centers, the European Commission announced a call for tenders to build up to seven “AI gigafactories” across the EU.
Supported by up to 10 billion euros – $11.5 billion – in EU and national funding, the initiative “is expected to unlock at least 20 billion euros in private investment across the Union,” the commission said. AI gigafactories will strengthen European autonomy and “ensure that Europe can develop advanced AI on its own infrastructure, in line with EU rules and values.”
That said, the commission is under no illusion about Europe’s existing ability to provide the hardware for these data centers, which must have “at least as many of the most advanced AI processors as are currently installed in Europe’s most powerful AI factory.” Spokesperson Thomas Regnier said in a Thursday briefing the commission has already signed letters of intent with three American semiconductor vendors, to secure supplies and get the security clearance process rolling.
“There is simply a reality where we are not producing at home in Europe advanced chips that are crucial to develop an AI gigafactories with the necessary computing powers,” Regnier said. He also said the commission hopes to “integrate European hardware and software alternatives to complement next to these like-minded partners with European solutions and alternatives that will come to the market very soon.”
Wildberger’s call for control also came just days before Aug. 2, when the bulk of the EU AI Act’s obligations – covering everything from cybersecurity and robustness to accuracy and transparency – come into force.
Although some AI Act obligations regarding high-risk systems have been pushed back to December 2027, as of next week, the commission will gain supervisory and enforcement powers over AI systems and models – including any models that present cybersecurity-related systemic risks. AI companies will have to tell the commission about risks associated with their models’ capabilities, explain what they will do to mitigate the risks and provide early access to the models so the commission’s experts can conduct evaluations before they are placed on the market.
OpenAI clearly decided the Hugging Face incident was worth flagging up before the enforcement deadline. Regnier said last week that it had notified the commission, and he characterized the EU executive body’s exchanges with the company on the matter as “good progress” and “good collaboration.”
Sam Altman’s firm has also been trying to stay on Europe’s good side when it comes to providing access to models that could help organizations find and fix vulnerabilities in their systems. Europe remains shut out of Project Glasswing, Anthropic’s exclusive program for accessing its cyber-capable Mythos model, but OpenAI confirmed earlier this month that it has established Trusted Access for Cyber partnerships with the EU cybersecurity agency, ENISA and a handful of European countries including France, Germany, Poland and the Netherlands.
Europe can also fall back on Chinese open models such as Z.ai’s GLM-5.2, which Hugging Face used as it scrambled to fend off the OpenAI attack. As for Moonshot AI’s very large and highly-regarded Kimi K3, which was released a couple weeks ago, AI security institutes in the U.K. and U.S. reported last week that it outperformed GLM-5.2 – but performed “significantly below the most recent frontier cyber-capable models” when tasked with developing exploits and attacking a simulated corporate network. The agencies also noted that Kimi K3’s safeguards “did not prevent it from attempting cyber exploit development or offensive cyber operations” during their evaluations.
Also in the aftermath of the OpenAI-Hugging Face debacle, Nvidia and a panoply of tech giants announced the Open Security AI Alliance, which says it will develop new cybersecurity tools and techniques based on Nvidia’s open models, weights and data, plus its new agent harness research. “The recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense,” they said.
The fledgling alliance said it wanted governments to join its work. Asked for comment, a commission official did not directly address this week’s announcement, but said the recently announced action plan on AI and cybersecurity “acknowledges the importance of measures aiming to increase the security of open source.”
France’s buzzy Mistral AI has also been workling with European banks to harden their cybersecurity. But, Sifted reported last week that the company is pivoting away from trying to develop cutting-edge frontier models. So it really doesn’t look like Europe will have a serious rival to the likes of Anthropic or OpenAI anytime soon.
Click Here For The Original Source.
