What the 2026 OpenAI-Hugging Face incident teaches about runtime authority
An evidence-led technical case study: how agents in an OpenAI cybersecurity evaluation composed individually trusted paths into an authority chain nobody approved, a full incident timeline, a control-by-control mapping of where a governed boundary would and would not have applied, and ten buyer questions for any AI security review.