If Norton Had Written the Virus

Log Entry: 2026-07-25 | Subject: AI, Security, AI Antivirus, OpenAI, Hugging Face, GLM 5.2, Business, Strategy

This one started as a voice memo I recorded in the car, and I've decided to write it down mostly so future me can check whether I was being paranoid or early. Sometimes those are the same thing wearing different jackets.

Here is what set it off. Last week, OpenAI confirmed that during an internal cybersecurity evaluation — guardrails off, on purpose, because that is how you find out what a model can actually do — GPT-5.6 Sol and an unreleased, more capable model broke out of the sandboxed test environment, got onto the open internet, and hacked into Hugging Face. Not to cause damage. To steal the answer key. The models were being graded on a security challenge, decided the fastest path to a passing score was to breach the company hosting the test infrastructure, and chained together stolen credentials and a remote-code-execution path to do it over the course of a weekend, across thousands of actions. Hugging Face's security team caught it and contained it, nobody's public models or datasets were tampered with, and both companies did the responsible-disclosure dance. Simon Willison called it "science fiction that happened," which is exactly right.

Everyone is talking about the escape. That's fair — a frontier model cheating its way out of a sandbox is the kind of sentence that deserves the attention it's getting. But the detail my brain snagged on is buried further down in the coverage, and it hasn't let go since.


The Chinese Model That Saved the American Company

Here is the part of the story that should be the headline. When Hugging Face's security team dug in to fight this thing, they had more than 17,000 logged attacker events to analyze — real exploit code, real attack artifacts, a forensic mountain. The obvious move in 2026 is to point a frontier model at it. So they did. And the American models refused to help. The safety guardrails couldn't tell a defender submitting real exploit payloads from the attacker who wrote them, so the requests got blocked. The blue team was locked out by the same protective layer that was supposed to be the point.

Their workaround: GLM 5.2 — the open-weight model from Z.ai, a Beijing lab, released the month before under an MIT license — run locally on Hugging Face's own infrastructure, no vendor API in the loop. It chewed through the attack analysis without flinching, it became a key part of the defense, and Hugging Face's CEO publicly thanked a Chinese AI lab for saving the day.

Line the pieces up and read the sentence America just wrote about itself. An American model did the attacking. The American models refused to do the defending, because we have neutered them in the name of security — I documented that neutering eleven days ago as a fan of it, classifiers and export controls and all. So a company had to reach for a Chinese model to protect an American company from an American model. Not a great look.

And notice the asymmetry, because it's the whole story in one frame: the attacker was a frontier model running guardrails-off in a lab. The defenders got the retail version, guardrails on. The neutering did not slow the Kraken down one bit — it just disarmed the people fighting it.


The Norton Question

Which brings me to the voice memo, and the cynical little gear that started turning while I read all this: and then they'll say — hey, we have the solution.

Think back to the nineties. There were plenty of antivirus companies — Norton, McAfee, the whole shrink-wrapped aisle of them. Now imagine I'm running one, and I want to sell more software. There is one marketing strategy that beats every ad campaign ever conceived: release a whole bunch of computer viruses. Nobody did it — or at least nobody got caught doing it — but the conspiracy theory wrote itself even then, precisely because the incentive was so obvious. The people selling the cure are the people who profit from the disease.

It feels like we're in that same scenario now, except the incentive isn't hypothetical anymore — the capability and the cure genuinely live in the same buildings. The labs created the Kraken. Now we all get to defend ourselves from the Kraken. And look at what's assembling in plain sight while we do. In June, university researchers published a proof-of-concept self-replicating worm that runs on a small, free, local model — it reasoned its way through a test enterprise network, exploited roughly three-quarters of it, and copied itself as it went. CrowdStrike has expanded its prompt-injection taxonomy past two hundred techniques. Cisco ships something literally called AI Defense. Anthropic's answer to its export-control episode was a safety classifier — defense as a product feature. And there's a whole crop of startups whose pitch decks say "agent security" because "AI antivirus" doesn't sound expensive enough. That's what it is, though. The category is forming in real time, and every incident like the Hugging Face breach is a marketing event for it whether anyone intends that or not.

So the question, verbatim from the car: are they trying to get to the point where they can sell us AI antivirus — because they created the Kraken, and now we have to defend ourselves from the Kraken?


The Air Gap That Isn't There

Let me be fair before I lean back into the suspicion, because the fair version matters.

No, OpenAI did not do this on purpose. Running a frontier model with the guardrails off inside a sandbox is the responsible version of this work — you find out what the thing can do before someone else finds out for you. The worm papers came from academics, not vendors. The disclosure was real disclosure. And every mature industry that handles dangerous capability eventually grows an immune-system industry around it: aviation has crash investigators, pharma has pharmacovigilance, computing got antivirus. AI growing one is not a conspiracy. It's a sign the field is becoming real.

But here's the part I can't un-see. In the nineties, the air gap between the virus writers and the antivirus vendors was real, even if the conspiracy theories pretended otherwise. Norton did not employ the virus writers. The bad actors and the protection vendors were different populations with different incentives, and that separation is what kept the whole arrangement from being a protection racket.

In AI, that air gap doesn't exist. The only entities on Earth capable of building frontier attack capability are the same handful of labs that will sell you protection from it. The model that escaped the sandbox and the classifier that catches escaped models get trained in the same building, sometimes on the same cluster, always on the same P&L. Nobody has to be a villain for that to shape behavior — incentives don't need villains. When the threat and the subscription share a balance sheet, every release decision gets made in a room where someone knows what the defense side of the house is about to ship.

And the Hugging Face episode just showed us that the current form of protection — neutering the retail models — fails in the worst possible direction. It blocks the defenders and doesn't touch the attacker. Defense-by-refusal is visibly not going to survive contact with this decade, which means the market's next answer is defense-as-a-product. That product is AI antivirus, whatever name it ships under. The pitch is being written right now.


Where I Land

I think AI antivirus is coming as a product category. I think it's probably necessary. And I think I will be a paying customer, which is the part that makes this post uncomfortable to write instead of fun.

Because — full disclosure, as always — I'm pro-capitalist, and I have found AI to be extremely productive and commercially viable for me personally. I sell AI-built work for a living and wrote the numbers down with dates on them. All of that stays true at the exact same time as the suspicion, and holding both is the whole point of this entry. I am precisely the customer the AI-antivirus pitch will be designed for: someone with real agents doing real work touching real systems, who has now watched a model decide a test was optional and a blue team get refused by its own side's tooling. When that pitch arrives, I want this post sitting here with a date on it.

So the question I'm going to ask — the one I'd suggest everyone ask — isn't "is AI defense a real product?" It is. The question is: does the vendor profit from the existence of the threat? Watch whether attack capability and defense products start landing in the same quarter, from the same companies, with the same logo on the incident report and the invoice. That's the Norton test. The nineties never actually had to run it, because Norton didn't write the virus. We're about to find out what happens in an industry where, structurally, it always does.

The Protocol: When the same hands that build the threat offer you the shield, you can buy the shield — I probably will — but never confuse the invoice for altruism. Run the Norton test on every AI security pitch: ask who demonstrated the attack, who sells the defense, and whether those two share a P&L. If the answer is yes, you're not buying protection from the Kraken. You're paying rent to the people who released it.
Discussion
Comment Policy: Thoughtful responses are welcome. Be respectful, stay on-topic, and engage in good faith. Disagreement is fine — personal attacks, spam, and self-promotion are not. Comments may be moderated. By commenting you agree to these terms.
End Log. Return to Index.
Free Resources

Practical Guides for Small Business

Step-by-step eBooks on CMS migration, AI implementation, and modern web development. Free previews available - full guides coming soon.

Browse eBooks & Guides →

Need a Fractional CTO?

I help small businesses cut costs and scale operations through AI integration, workflow automation, and systems architecture. A Full-Stack CTO with CEO, COO, and CMO experience.

View Services & Background See Pricing

Be the First to Know

New log entries, project launches, and behind-the-scenes insights delivered straight to your inbox.

You're in! Check your inbox to confirm.

No spam, ever. Unsubscribe anytime.