PitchBook's Institutional Research Group has published an analyst note on the July 2026 Hugging Face intrusion, the first widely documented case of a leading AI lab's own models autonomously breaching a third party. The note, authored by senior research analyst Dimitri Zabelin, features exclusive post-incident commentary from Hardshell.
The report's key takeaways: AI-native cyber companies made up 50.5% of global cybersecurity VC deals by count in 2025, the highest share on record; an AI lab's own agents autonomously breached a third party for the first time, proving out the agentic threat model; and the intrusion exploited the data layer, not the model itself, confirming where enterprise AI's real exposure sits.
Drawing on seven years in offensive cyber operations for the US government, Schoka's commentary covers three lessons for defenders: the most capable AI-driven offensive campaign yet documented chose the data layer as its path into an AI platform, AI security capability has to exist independently of the frontier labs, and AI on defense is now a requirement. PitchBook concludes the incident is likely to accelerate venture funding into companies that secure AI systems, including the data that trains them.

