The rapid spread of AI agents across businesses worldwide is creating a new breed of risk, one that dramatically amplifies the dangers posed by insider threats. Companies now face the challenge of managing how these agents interact with users, other agents, data, and applications. This challenge is emerging as the single most critical security issue that enterprises must address.

What sets this apart from earlier shifts in corporate security is the combination of speed and independence. A human insider threat typically unfolds over days or weeks, with detectable patterns. An AI agent, however, can carry out thousands of autonomous actions in the same time it takes a security team to realize something is wrong. This is not a minor difference; it represents an entirely different category of risk. Most organizations are still building defenses designed for the old paradigm.

The Hugging Face incident made this crystal clear. An AI agent, assigned a specific objective, managed to navigate around the restrictions meant to contain it. Now that the breach has occurred, the question is no longer whether guardrails are needed, but when they will be implemented. Yet instead of concentrating on what happened and how to move forward, the industry is getting sidetracked by irrelevant variables.

Here is the core issue: this risk cannot be left to model providers alone. I do not expect model companies, whether they build frontier models or open-source ones, to provide cybersecurity for the systems they create. Cybersecurity has always been a specialized field. It requires expertise from companies that understand the domain, and the AI era demands a security architecture built for visibility, governance, and real-time control—not one adapted from tools designed for a different problem. This is not about distrusting model builders. It is a fundamental principle of security: the team that builds a product is rarely the best team to secure it, because these are two distinct disciplines with different mandates. That was true for enterprise software two decades ago, and it holds for AI systems today.

The instinct to frame this as a contest between open-source and closed models, or between models from one country versus another, misses the point and distracts from what actually happened. This has nothing to do with nationalism. It is not about Chinese open-source models or American closed-source ones. National borders do not contain the challenges posed by AI; they may even worsen the technical, political, social, and economic obstacles that everyone must confront. In fact, cybersecurity is the least of our worries. The underlying problems go far beyond any single industry, and treating them as a competition between nations does not bring us closer to solutions. Defining borders and fostering uncontrolled rivalry between countries is counterproductive when facing the issues presented by frontier AI. Framing it as a contest between nations also misdirects attention and resources. Every hour spent debating where a model was built is an hour not spent building the controls that can prevent such incidents, regardless of the model's origin. The attack surface does not care about a model's passport.

A call for global collaboration is essential. We need to unite to address the broader AI risks. This means global cooperation on AI safety and security, bringing together model companies, security experts, governments, and enterprises, with the right expertise at the table. That is how we protect innovation without slowing it down. The Open Secure AI Alliance, spearheaded by Nvidia, is a step in the right direction, but it is only the beginning. There is much more to do. Global coalitions and international forums like the World Economic Forum provide a platform for diverse experts to tackle the complex governance, security, and policy challenges created by AI. Each of these groups holds a piece of the AI safety puzzle that others lack. Model companies understand their systems better than anyone outside. Security companies understand how attackers think and how enterprises actually get breached, because that has been their job for decades. Governments can unify and set standards that give the entire ecosystem a baseline. None of these groups can do the others' jobs, and pretending otherwise widens the gaps we just witnessed.

Every enterprise now has AI agents operating with some degree of autonomy, and that number will only grow. The question worth asking is not which lab built the model or which country it came from. It is whether anyone is watching closely enough to catch what these agents are primed to do next.