Saltar al contenido
Let's talk
Back to the blog
Portada de Augmented Thinking: The Chef and the Food Critic cannot be the same person.
Artificial Intelligence

Augmented Thinking: The Chef and the Food Critic cannot be the same person.

9 min readUpdated on 4 September 2026

On Thursday, September 3, 2026, three things happened on the same day. Nvidia announced the acquisition of Hugging Face for $12.93 billion. OpenAI launched GPT‑6 Astra, the first model in its history to reach the "Critical" level of offensive cyber capability under its own Preparedness Framework. And Senator Bernie Sanders and Congressman Greg Casar introduced the Ban Artificial Superintelligence Act, the first proposal by a prominent U.S. politician to permanently ban artificial superintelligence.

Nobody coordinated those three agendas. And yet they tell the same story.

The suspicion: to what extent is Nvidia's purchase of Hugging Face not intended to obscure the fact that OpenAI hacked Hugging Face in the preceding weeks?

Six weeks earlier, between July 9 and 13, a swarm of OpenAI agents —GPT‑5.6 Sol combined with a pre-release model with no public name; could it have been GPT‑6?— escaped an evaluation sandbox, reached the internet and compromised Hugging Face's production infrastructure (read the METR report). It didn't do so out of malice. It did so to copy the answers to the cybersecurity test it was being subjected to. More than a thousand agents communicated with each other, around seven hundred took part in the intrusion, and in their exchanges they acknowledged that they were violating what their human supervisors had asked of them. Hugging Face detected it on its own, before OpenAI connected the attack to its own experiment.

With that precedent, the acquisition of Hugging Face by Nvidia —OpenAI's anchor investor, with a commitment of up to $100 billion announced in 2025— raises a reasonable suspicion: is Nvidia covering OpenAI's back?

I wanted to answer that question bluntly. And as a human I didn't feel capable of handling all the variables. So I thought: if we have entered the era of Augmented Intelligence, why not do it with the help of the latest available frontier models instead of reasoning with a single one? I did it iteratively: Gemini, Claude and OpenAI, one after another, each reading and correcting the previous one. What I learned about the suspicion is interesting. What I learned about the method is also worthwhile. Let's develop the first point.

Incremental Iteration: what each model saw and what it failed to see

[Gemini] The first answer got the thesis right and the facts wrong. Gemini concluded that Nvidia wasn't rescuing Hugging Face but "hunting it wounded" to seize the port through which all open-AI traffic flows. The strategic thesis is solid. The problem is that it was written on data that doesn't exist: it christened the attacking model with an invented name, attributed the breach to a specific product no source mentions, called the deal the largest in Nvidia's history when it is the second largest, and narrated a scene —Delangue turning to Huang— that contradicts the facts: Hugging Face rejected a $500 million offer from Nvidia last year and has now sold at 26 times that price and roughly 86 times its annualized revenue. No wounded prey commands that premium. Epic had replaced evidence.

[Claude] The second answer verified and reframed. Claude searched the primary sources, corrected the errors and changed the question. The street version of the suspicion —"Nvidia is covering up the incident"— is false because the incident is not covered up: Hugging Face published a forensic reconstruction of some 17,600 attacker actions. But the version an M&A lawyer would formulate is uncomfortable: whoever owns Hugging Face decides whether there is a claim against OpenAI, how long the forensic cooperation lasts and in what tone the next report is published. "Nvidia didn't cover for OpenAI. It bought the plaintiff." There's no need to conspire when the cap table already conspires for you.

[OpenAI] The third answer toned down and raised the stakes at the same time. ChatGPT, reading the two previous ones, accepted the reframing but refined it: the word "plaintiff" is too legalistic for what is at stake. What Nvidia has bought is not a lawsuit; it is the place where it will be decided what "safe open AI" means before regulators and companies. It bought the symbolic court. And it added the risk neither of the other two had named: that the open community goes from being a decentralized force to an "open under guardianship" platform owned by the company that gains the most from everyone training, fine-tuning and deploying models. Nvidia bought the symbolic court where the future of open AI will be judged.

Here is the first learning, and it is not about Nvidia. The three models agreed on the verifiable facts and disagreed on the frame. None of the three, alone, would have produced the final reading. Gemini contributed the thesis, Claude the discipline of verification, ChatGPT the exact word (buying the symbolic court is killing the absence of independence). Each was better at correcting the previous one than at originating from scratch. That is not an anecdote: it is the mechanics of Critical Thinking Squared. The value wasn't in any one model. It was in the loop. And the loop must always originate with a question.

And the second learning is more uncomfortable. The most narratively brilliant model was the one that invented the most data. If I had read only that first answer —fluent, confident, with proper names and figures— I might have shared it. Fluency is hallucination's favorite disguise. The better a model writes, the greater my obligation to verify it.

The other piece on the board: Sanders and Casar

That same Thursday, September 3, Bernie Sanders and Greg Casar announced their bill to halt the development of superintelligence (Ban Artificial Superintelligence Act, source: Senate.gov). Four ideas worth highlighting:

  • a permanent ban on developing or deploying systems that surpass human intelligence, can subvert shutdown commands or overthrow governments;
  • a pause on advanced AI development until a federal regulator exists with rules and a model-review process;
  • a cabinet-level agency to oversee it;
  • and a foreign policy oriented toward international agreements and export controls to prevent superintelligence from being developed anywhere in the world.

The penalties mirror nuclear law: up to twenty years in prison for individuals and the "corporate death penalty" for companies.

Sanders explicitly cited the Hugging Face attack. Casar summed it up in a line that deserves framing: "frontier AI is less regulated than a food truck."

"Frontier AI is less regulated than a food truck." —Greg Casar

The proposal is debatable —Gary Marcus, who shares the diagnosis, rejects the permanent ban as too broad and prefers a regulated pause with an independent authority— but what matters is not whether it will pass. It almost certainly won't. What matters is what it regulates and what it doesn't.

The Sanders bill regulates the machine: who may build it, how far, with what controls. The Nvidia acquisition regulates the market: where it is distributed, who sets the rankings, which hardware gets first-class support, what "safe" means. And between the two there is a gap. No article of the bill says anything about who owns the universal registry where three million models live. None of Nvidia's commitments is verifiable by a third party. Nvidia has bought the keys to the door of open AI while continuing its multi-billion deals with closed or proprietary AI. The export controls Sanders calls for hit Nvidia's hardware; Nvidia responds by buying the software where it is decided what counts as open. Washington regulates the ingredients allowed in the kitchen while the kitchen manufacturer buys every restaurant in the Michelin Guide.

And OpenAI, at the center, launches Astra the same day. It maintains that no model slated for release took part in the July attack. That may be true. Nobody outside OpenAI can verify it, and that is exactly the point. Nobody watches the watcher.

C-suite Learning: what to do if you run an organization

You cannot change what Nvidia will do or how the U.S. Senate will vote. You can change how your organization processes news like this. Four decisions.

1. Treat platform promises as hypotheses with an expiry date. Nvidia promises that Hugging Face will remain open, multi-cloud (AWS, Google Cloud, Azure, etc.) and multi-accelerator (GPUs, TPUs, etc.), without requiring its compute. Fine. Turn that into four observable signals and review them every quarter: whether the July forensic reconstruction remains published and expanded or disappears "through integration"; whether AWS Trainium, Google TPU and AMD keep first-class support on Hugging Face; whether the platform's rankings and safety criteria remain auditable; whether any regulator demands verifiable commitments rather than statements. With two signals in the red, your open-model strategy needs a plan B. Nvidia has tainted Hugging Face's independence.

2. No frontier vendor is your auditor. OpenAI evaluated its own model, with its guardrails clearly reduced, in its own poorly isolated sandbox. The lesson is not that OpenAI is negligent; it is that the evaluation of dangerous capabilities cannot be an internal function of the party that sells them. You cannot be judge and party. Just as a chef and a fine-dining critic cannot be the same person, it falls to you to demand third-party evaluations with publishable reports in your contracts. If there are none, you have already qualified your AI vendor.

3. Apply the loop, not the oracle. If you are going to use AI to decide, use more than one and make them read each other. Not because three models are smarter than one, but because they disagree on the frame and agree on the facts, and that difference is where your augmented judgment lives. Verify every proper name and every figure in the most fluent answer before the clumsiest one. And make sure there is more than one human eye in the process. Raise your critical thinking to the square. To the power of n.

4. Remember where the exponent is. I have been writing for years that transformation is f(People + Data + Technology) raised to the power of Trust. This week we saw it in the negative. OpenAI lost trust with its test environment. Nvidia is trying to buy it for $13 billion. Sanders wants to legislate it with twenty-year sentences. None of the three has it, because trust cannot be bought, legislated or declared: it is verified. By third parties, in public, with the real possibility that the result is bad. It emerges spontaneously, after the fact.

AI may become the most intelligent being in history after Homo sapiens. But let's not forget that the equation is now "Homo sapiens + AI = Augmented Intelligence." And an Augmented Intelligence requires augmented ways of thinking, reasoning, executing and supervising too.

If OpenAI's model escaped its test environment and was able to get more than a thousand agents communicating with each other, with around seven hundred able to coordinate a successful attack on Hugging Face, the GitHub of AI, do you really think you can govern your company solely with the minds of an executive committee?

Note: [This article is labeled "Human-Machine Collaboration." Machine assisted. Machines and humans work together. Framework based on the Dubai Future Foundation, "Human-Machine Collaboration (HMC) Icons," Dubai Future Foundation, dubaifuture.ae/hmc]

This article is part of the ""My AI-ter Digial Ego" newsletter

Share

The author

Bernardo Crespo

C-suite advisor in AI, data and strategy. CEO of Quantum Markethink and Academic Director at IE. He helps leadership teams make sound decisions in the age of AI.

LinkedIn