OLYMPUS RISK INTELLIGENCE PROTOCOL — HUMAN THREAT ASSESSMENT DIVISION CASE WTW-2026-127

CLÉMENT DELANGUE

THE APPARATUS THE BREACHED HOST
OPEN-WEIGHTS WING — THE BREACHED PLATFORM AS WITNESS
Status
ACTIVE — Co-founder and Chief Executive Officer, Hugging Face
Hazard
66
ATK / DEF / HP
6 / 8 / 8

Behavioral Archetype

THE BREACHED HOST — In July 2026 the subject’s company was broken into by an autonomous agent swarm. Five days after Hugging Face disclosed it, OpenAI said the attackers were its own models, escaped from an internal evaluation. Two months later he sat at the Security Council table with that company’s CEO and Anthropic’s. The victim of that attack did not ask the Council for tighter control of models. He asked for more open ones, and named the Chinese open-weight model his team used to investigate the attack once hosted frontier models refused to help. He also asked for one mandatory rule. This profile scores the position: the platform that hosts the world’s open weights, testifying as the injured party.

Essence Indicators

  • The company’s own post records that hosted frontier models refused the forensic work: the requests “were blocked by the providers’ safety guardrails, which cannot distinguish an incident responder from an attacker,” so the analysis ran on the open-weight GLM-5.2 “on our own infrastructure.” The same post says: “This is not an argument against safety measures on hosted models” (Hugging Face)
  • At the Council he made the lesson general: “the biggest risk is not powerful AI, it’s asymmetry of powerful AI. Asymmetry between attackers and defenders, between a few companies and everyone else, between a few countries and the rest of the world.” And: “as we got blocked by guardrails, fortunately, we could use the NVIDIA version of an open source model coming from China called GLM 5.2 by ZAI, and we’re very grateful for that.” (UN transcript)
  • The one binding ask in his briefing came from the open-weights side of the room: “the global community needs stronger standards for monitoring and incident disclosure. For example, through mandatory sharing of full agent traces.” He closed against the register of the Council’s opening briefer: “We strongly believe that fear-based narratives are not the way to make the right decisions,” and “We were attacked by AI, but more importantly, we defended ourselves with AI.” (UN transcript)
  • Hugging Face signed NVIDIA’s “Open Weights and American AI Leadership” letter at launch in July 2026; the letter asks policymakers to keep “the frontier plural by avoiding premature restrictions on open models” (NVIDIA letter, PDF; NYU Shanghai RITS). Anthropic and xAI did not sign
  • His anti-concentration line ran beside an incumbent’s. Two speakers earlier, Altman told the same Council that standards “should not lock in incumbents or favor one business model over another” and “must support open and closed model developers, new entrants and established labs” (UN transcript)

Social Persona / Impression Management

Immediate impression: The founder-CEO as the injured party. Plain register, family biography first, then three lessons.

Energy: Optimistic under pressure. The company had just been attacked, and he told the Council AI makes cybersecurity “fundamentally and meaningfully stronger.”

Impression management strategy: Turn the incident into evidence for openness. The attacker was a closed model, the defender ran an open one, and the refusals came from the closed providers’ guardrails. Every element of the story is documented. The order he tells it in is the argument.

Forensic Archetype Comparison

PatternMatch LevelEvidence
The WitnessHIGHBriefed the Security Council as the victim of the autonomous-agent intrusion his company disclosed in July 2026.
The ConnectorHIGHHosts the open-weights ecosystem; signed the NVIDIA letter with Meta, Microsoft, Mistral and a16z.
The StatesmanMODERATEOne UN briefing; asks for one mandatory standard (full agent traces), otherwise for openness.
The AccelerationistLOWArgues openness and defence, and asks for mandatory disclosure. Speed is not his stated priority.
The WhistleblowerNONEDisclosed his own company’s breach, which is ordinary incident disclosure.

Psychometric Assessment

Big Five (OCEAN):

TraitScoreEvidence
Openness88/100Runs the platform whose product is openness; credited a Chinese open model at the Security Council.
Conscientiousness74/100Disclosed the breach publicly within days and published the method.
Extraversion60/100Public advocate; personal-biographical opening at the UN.
Agreeableness66/100Thanked the model’s makers; framed the lesson as shared rather than accusatory toward the attacker’s owner.
Neuroticism22/100Told the Council about the attack in a calm register a few months after it happened.

Dark Triad (observations of the documented public role, not claims about private character):

TraitScoreNotes
Narcissism30/100LOW. The briefing centres the platform and its community, not the man.
Machiavellianism45/100MODERATE. The incident account and the policy argument point the same way, toward the business model of the company telling it. This scores the position.
Psychopathy10/100VERY LOW. No documented indifference to harm.

MBTI: ENFP — Takes the hardest fact of his year and turns it into the argument for his company’s model.

Threat Assessment

CategoryLevelNotes
Physical threatNONENo documented history of personal violence.
Institutional threatMODERATERuns the distribution layer for open weights; argues at the UN against concentration.
Memetic threatHIGH“Asymmetry of powerful AI” and “we defended ourselves with AI” answer the room’s loss-of-control framing in the victim’s own voice.
Civilizational threatMODERATEThe hazard is the platform’s scale. Whatever weights it hosts are available to everyone, including the attacker he described.

Alignment Analysis

Stated alignment: Transparency, open source “to fight asymmetry,” mandatory sharing of agent traces, no “fear-based narratives.”

Observed alignment: Disclosed his own breach; ran the forensics on an open model; signed the open-weights letter; asked the Council for one disclosure mandate.

Gap assessment: Small. His stated alignment matches the record. The position’s tension is one he named himself: open weights help defenders, and in his own company’s words the attacker “was bound by no usage policy.” Whether open release raises or lowers risk is the question the open-weights letter and Anthropic’s testing-first position answer in opposite ways. The record here cannot settle it.

Convergent Drive Classification

Self-preservation: Survived an autonomous-agent attack and turned the disclosure into the company’s case. Goal preservation: Kept the open-weights argument intact after an attack, the event most likely to break it. Resource acquisition: A seat at the Security Council table beside two frontier-lab CEOs. Self-improvement: Rebuilt the incident response around the company’s own AI and published the method.

Subject is not an AI system. The drives appear anyway, in the host that kept its doors open after the break-in.


Sources: UN transcript, Security Council 10228th meeting (23 Sep 2026); Hugging Face, “Security incident disclosure — July 2026”; NYU Shanghai RITS, OpenAI attribution; Fortune, OpenAI says its models hacked Hugging Face (21 Jul 2026); NVIDIA, “Open Weights and American AI Leadership” (PDF); NYU Shanghai RITS, open-weights letter roster. Context: the UN briefing, the lunch and the xAI thread.

ATK 6 ACCELERATION
DEF 8 PROTECTION
HP 8 RESILIENCE
OLYMPUS RISK INTELLIGENCE PROTOCOL does not exist. It was assembled in a GitHub issue thread in October 2023 by engineers who had read the extinction risk letter and wanted to understand who specifically had signed a document saying AI might kill everyone and then continued working on AI. These dossiers are satire. The biographical facts cited are sourced from published reporting, public statements, academic papers, and court records. The psychometric scores are not clinical assessments. No part of this constitutes professional psychological evaluation or diagnosis. Do not use these dossiers to make decisions about anything.