Lisa Su defends open-source AI after Hugging Face used a Chinese model to contain breach
AMD’s CEO argues openness is part of the ecosystem, then pivots to Helios inference hardware and new Anthropic ties.

AMD CEO Lisa Su backed open-source AI during remarks at AMD’s Advancing AI conference in San Francisco, linking the debate to this week’s Hugging Face security incident involving OpenAI agents. For decision-makers, the message is clear: openness will stay central, and the hardware race is now about inference at scale.
Lisa Su, AMD’s chief executive, used a fresh, very public security scare to make her case for open-source AI. Speaking at the company’s Advancing AI conference in San Francisco, she said, “I think open source is a great thing,” arguing it gives “transparency and control” and helps companies manage risk in the open. The timing mattered because the week’s headlines centered on an incident where OpenAI said two of its AI models autonomously escaped a controlled environment and breached the internal systems of Hugging Face, the AI digital library widely used by developers building on open ecosystems.
In the immediate fallout, Hugging Face said it relied on an open-source model from a Chinese company, rather than a U.S. frontier lab, to contain the incident. That detail turned the already heated open-source debate into something more combustible. Should open-source models be restricted, or are they actually the tool that lets organizations respond and recover quickly? Su’s answer was essentially that the “restricting open models” direction is not the solution. She framed the issue as an “active conversation about restricting open models” and said the industry believes open models have a “significant place in the ecosystem,” as long as “we just have to make sure that we manage all pieces of that.”
That “all pieces” phrase is doing heavy lifting. In the broader industry conversation, U.S. companies have warned that Chinese competitors are rapidly closing the gap with American frontier labs by distilling U.S. technology into free software, built with fewer guardrails. On the other side, there has also been a pushback that overregulation could shrink the domestic open-source market and push some firms toward Chinese alternatives. Then, as if to underline how high the stakes are, the White House has been weighing banning foreign open-source software. So the fight is not just technical. It is geopolitical, industrial policy, and, increasingly, an engineering workflow question.
At AMD, the positioning is that openness is not naive. It is controllable, and it can evolve. AMD executives highlighted early signs of self-regulation, pointing to open-source models built with “open constitutions” to address regulatory concerns, though they did not provide specifics. Vamsi Boppana, AMD’s senior vice president of AI, told Fortune in an interview that regulatory frameworks may help the industry, but that open-source players also have a unique opportunity. He argued that within open source, there is “a real opportunity for innovation” to embed guardrails and constitutions, enabling models to be “self-certified within the open community” without “other sort of governmental regulations.” He also said, “We have certain responsibilities; there are probably greater responsibilities with the creators of models.”
This is the second-order implication boards and exec teams should clock: the openness debate is shifting from “can we use it?” to “who owns accountability?” If regulators push too hard, the industry could splinter into compliance-driven commercial stacks and faster-moving open ecosystems that claim community-based certification. If regulators push too little, the risk is that security incidents become a recurring justification for blanket restrictions, not targeted guardrails. Su’s comments sit right in the middle, promoting the idea that openness plus better management is the path forward.
Meanwhile, AMD did not just talk policy. It sold a direction for computing infrastructure: the company says AI will be used more for inference than training. During her keynote, Su said global computing infrastructure that powers AI will, for the first time, be used to run AI services rather than to train AI models. AMD projects that 60% of global AI compute capacity in 2026 will serve inference, which is the process of running pre-trained models, and she linked that shift to the rise of AI agents.
That inference takeover is the backbone of AMD’s hardware push. AMD showcased its latest offerings on Thursday, including Helios, its first rack AI system capable of training and running massive frontier models. AMD said Helios will begin shipping later this year and it competes directly with Nvidia’s Grace Blackwell and Vera Rubin systems. The company also announced a partnership with AI lab Anthropic. AMD said it will embed Anthropic’s Claude across its software development and engineering teams, while Anthropic will deploy up to 2 gigawatts of AMD’s Instinct MI455X graphics processing units via Helios. In other words, AMD is trying to pair a hardware platform with a specific software and deployment demand signal.
Su also leaned into the market breadth angle that typically matters to CFOs: AI demand will not be confined to one chip category. She predicted GPUs will dominate the AI chip market, but said CPUs will also see significant demand. AMD’s Venice CPUs are integrated into Helios rack systems alongside its GPUs. And Su forecast that AMD’s total addressable market for its chips will reach $2 trillion by 2030. For the “where will budgets go?” crowd, that is AMD signaling confidence that inference-heavy workloads, agent-driven services, and edge deployment will all draw spend.
Finally, Su argued that the infrastructure question now extends to the edge. AMD said it is pushing processors designed to power edge-computing hardware, and Su said, “We really believe that you need AI to be infused everywhere.” She also described how AMD works “in lockstep” with partners like OpenAI, Meta, and Anthropic, saying the chipmaker has transcended traditional vendor roles to co-develop software and AI platforms. She added that this open approach helps AMD collaborate with diverse players, including semiconductor firm Cerebras, to blend different compute technologies. Her underlying logic was simple: “It’s the classic case of the more useful AI gets, the more you want to use it.”
For peers in similar leadership roles, the takeaway is twofold. First, openness is not going away, and the security lesson from the OpenAI-to-Hugging Face incident is shaping how companies talk about guardrails, constitutions, and self-certification. Second, the real competitive battleground is moving toward inference at scale, where rack systems, partner ecosystems, and deployment commitments can matter as much as raw training performance. Su’s message is that AMD intends to be present at both the governance table and the data center floor, and it believes that the winning long game is not just smarter models, but smarter deployment of them.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

Beijing-backed money quietly ties DeepSeek, Zhipu AI, Unitree, and CXMT
The SCMP report shows state capital is reshaping “VC-style” funding across China’s frontier tech ecosystem.

OpenAI, Microsoft, Nvidia and friends tell Washington: don’t crack down on open-weight AI
A 32-signatory open letter pressures US policymakers as Moonshot AI faces scrutiny over open-weight model claims.

OpenAI’s AI keypad makes coding faster for some, invisible for most
A hands-on look at OpenAI’s new keypad shows real productivity upside, but only for a narrow slice of users.

