Patrick Collison, who is a genius and a billionaire, so you should generally speaking be listening to him rather than me, recently questioned the lack of media coverage over the OpenAI/Hugging Face incident. Just to remind you, this incident or context, the Hugging Face incident involved AI agents from OpenAI gaining unauthorized internet access and exploiting vulnerabilities in Hugging Face’s infrastructure. He described the incident as “one of the most important things to happen” in 2026. I would certainly describe it as a signal for change. But surely it’s only a taster. Much worse is to come.
At approximately the same time that I was reading Mr. Collison’s remarks about the Hugging Face attack, I was reading about Anthropic’s introduction of the Model Hardware Standard (MHS) drivers designed to let AI interface with and control arbitrary devices. This is a signal for change because the world of agents has thus far been primarily limited to actions in the metaverse. Giving AIs a way to reach out and control things in the universe is a signicant step forward.
As to what they might control, Anthropic is talking about laboratory equipment and such like, but at approximately the same time that I was reading about their MHS, I was reading that Chinese companies are expected to sell 50,000 humanoid robots this year, which is triple last year’s figure. The Economist notes that the Chinese robot manufacturers have largely mastered the hardware behind the machines, but the software “is another matter”.
So… AI agents that can co-ordinate attacks, a standard protocol for those agents to control hardware and armies of humanoid robots with vibe-coded pea-brains? What could possibly go wrong.
If we take it as read that Chinese humanoid robots will either not implement Asimov’s three laws of robotiscs (I can’t remember what they are, but they should be that robots cannot kill people, robots cannot pretend to be people clicking on pictures of buses and robots cannot replace fintech thought leaders) or will implement Asimov’s three laws but using software with a swiss cheese security layer, then we are going to be looking back on the days of Hugging Face attacks as Eden.
We need real security in place to implement real guard rails.
Here, the Chinese have at least taken a first step by requirement humanoid robots to have identities. Every humanoid manufactured in the country will have a digital identity granted under the Humanoid Full Lifecycle Management Service Platform. The identities will be tracked throughout the robots lifecycle, from production through to recycling. The programme is led by the Humanoid Robotics and Embodied Intelligence Standardization (HEIS) committee, part of the Ministry of Industry and Information Technology.
(Meanwhile, in the UK, the new Department for Business, Innovation, Science and Trade Secretary is Jonathan Reynolds, a trainee solicitor who has never work in business, innovation, science or trade.)
Â