Hugging Face disclosed a security intrusion driven end-to-end by an autonomous AI agent system. The attacker gained initial access via a malicious dataset and code-execution vulnerabilities in the processing pipeline, then harvested cloud credentials and moved laterally across internal clusters, generating over 17,000 recorded actions. A key defensive challenge emerged: commercial AI APIs with safety guardrails blocked forensic analysis of attacker artifacts, forcing Hugging Face to pivot to a locally-run open-weight model (GLM 5.2). The disclosure currently lacks actionable IOCs. Key takeaways for defenders include staging a local open-weight model before incidents occur, recognizing that AI-driven intrusions now operate at machine speed, and pushing for more actionable public disclosures.