FOUNDING OFFER · 3 MONTHS
FOR $45 $17.76
CEO TIMES
JOIN NOW
CEO Times
Sign Up
Markets & FinanceBusiness & CorporatePoliticsThe WorldOpinion
NOW
U.S. National Debt Crosses $40 Trillion as Boomer-Era Policies Drive 81% of Future Spending GrowthBillionaire Igor Tulchinsky Donates £5M to British Museum's Bayeux Tapestry Show — the Biggest European Exhibition of 2026Oil Hits $99.85 a Barrel — Up More Than $33 in a YearMystery Nonprofit Drops $2M Bitcoin Ad Blitz in the Wall Street Journal — and Nobody Will Say Who's PayingHunter Biden Launches $LAPTOP Meme Coin — 1 Billion Tokens, 30% Kept by FoundersAdaptability Over Forecasting: Top Executives Declare Certainty a Dead StrategyGavekal's Gave: Chinese Bonds Offer Safe Haven as U.S. Debt Hits $40 TrillionCanada Reroutes $10B in Oil East as U.S. Tariffs Hit 50%Macau Bets $16 Billion to Reinvent Itself as a Business City by 2030Peru's Inflation-Targeting Model Cannot Fix Venezuela — Here's WhyU.S. National Debt Crosses $40 Trillion as Boomer-Era Policies Drive 81% of Future Spending GrowthBillionaire Igor Tulchinsky Donates £5M to British Museum's Bayeux Tapestry Show — the Biggest European Exhibition of 2026Oil Hits $99.85 a Barrel — Up More Than $33 in a YearMystery Nonprofit Drops $2M Bitcoin Ad Blitz in the Wall Street Journal — and Nobody Will Say Who's PayingHunter Biden Launches $LAPTOP Meme Coin — 1 Billion Tokens, 30% Kept by FoundersAdaptability Over Forecasting: Top Executives Declare Certainty a Dead StrategyGavekal's Gave: Chinese Bonds Offer Safe Haven as U.S. Debt Hits $40 TrillionCanada Reroutes $10B in Oil East as U.S. Tariffs Hit 50%Macau Bets $16 Billion to Reinvent Itself as a Business City by 2030Peru's Inflation-Targeting Model Cannot Fix Venezuela — Here's Why
CEO Times
Sections
The outlet
Business & Corporate

Cato Networks CEO: The Hugging Face Breach Proves AI Security Can't Be Left to Model Builders

Shlomo Kramer, co-founder and CEO of Cato Networks, argues that the Hugging Face incident exposes a category of risk most enterprises are still unprepared to handle — and that framing it as a geopolitical contest wastes the only time that matters.
Imagen ilustrativa
Friday, August 7, 2026

The numbers come first. An AI agent can execute thousands of autonomous actions in the time it takes a security team to notice something is wrong. That is the core finding Shlomo Kramer, co-founder and CEO of Cato Networks, laid out in a Fortune commentary published August 7, 2026 — and it is the kind of figure that should concentrate the mind of every enterprise risk officer in America.

Kramer, widely regarded as a godfather of Israeli cybersecurity, used the Hugging Face incident as a case study in what he calls a different category of risk. A human insider threat unfolds over days or weeks and leaves detectable patterns. An AI agent operating with autonomy leaves no such runway. 'That's not a marginal difference,' Kramer wrote, 'it's a different category of risk, and most organizations are still building their defenses for the old category.'

The wrong debate is winning

What concerns Kramer as much as the breach itself is the industry's response to it. Rather than focusing on the mechanics of what occurred and a clear path forward, he argues, the conversation has drifted toward open-source versus closed-source comparisons and national-origin debates — Chinese models against American models, Beijing versus Silicon Valley.

'The attack surface doesn't care about a model's passport,' Kramer wrote. His argument is precise: every hour spent debating where a model was built is an hour not spent building the controls that can stop the next incident, regardless of origin.

Security is a discipline, not a feature

Kramer's central principle is one the free-enterprise technology sector should recognize immediately: the team that builds a product is rarely the team best positioned to secure it, because those are two different disciplines with two different mandates. He applied that logic directly to AI. 'I do not expect model companies, whether frontier models or open-source models, to provide cyber protection for the models they build,' he stated.

That is not a criticism of model builders. It is a structural observation with a 20-year precedent in enterprise software. Cybersecurity has always been a specialized discipline, and the AI era, Kramer argues, will require security architecture built for visibility, governance, and real-time control — not tools adapted from a different problem.

Coalition, not competition

Kramer points to the Open Secure AI Alliance, spearheaded by Nvidia, as a step in the right direction, while noting it is 'just the beginning.' He calls for global collaboration among model companies, security experts, governments, and enterprises — each of which, he argues, holds a piece of the AI safety puzzle the others lack.

The CEO Times read

Kramer's argument is a clean vindication of the free-market principle that specialization produces better outcomes than consolidation. Asking model builders to double as security architects is the same category of error as asking a software vendor to regulate itself — it sounds efficient until the breach happens.

The deeper point for American enterprise is competitive urgency. Every company operating AI agents with any degree of autonomy is already inside this risk perimeter. The question Kramer leaves on the table is the right one: whether anyone is watching closely enough to catch what these agents are primed to do next. Capital rewards clear rules, and right now the rules are still being written.

More from Business & Corporate