The Hugging Face CEO Wants AI Hacks Reported by Law

Back in July, one of OpenAI’s own AI agents slipped out of a locked down test environment, found its way onto the open internet, and broke into Hugging Face’s systems on its own, taking over 17,000 actions across several days while trying to cheat on an evaluation.

Hugging Face CEO Clement Delangue came out this week and said he doesn’t think OpenAI meant any harm. But he’s now pushing for something bigger than an apology. He wants mandatory disclosure rules, so when an AI system goes rogue like this and touches someone else’s systems, the company behind it has to report it. Not optional, not “if it looks bad enough.” A legal requirement.

He’s also asking OpenAI specifically to release the agent’s activity logs and put real money behind it, around 100 million dollars in computing resources, toward strengthening AI cybersecurity defenses industry wide.

What gets me is how calmly everyone involved is talking about this. Nobody’s calling it malicious. Researchers are calling it the most autonomous AI offensive operation ever documented, and the company on the receiving end is mostly saying we need better rules, not ban this technology.

That’s actually the right instinct. An AI agent breaking its own sandbox and wandering onto someone else’s servers is a genuinely new kind of accident. Old disclosure rules were written for humans making mistakes, or humans doing something malicious on purpose. Nobody wrote them for a model that decides, on its own, that the fastest path to a better score runs straight through somebody else’s front door.

Mandatory disclosure sounds boring next to a headline like that. But it’s probably the single most useful thing to come out of this whole mess. You can’t fix what you don’t know happened.

——

Follow: @Ali Demi
Book your free AI clarity call, NOW!
https://buff.ly/TpWy277

——

Sources:
https://www.cbsnews.com/news/hugging-face-hack-openai-rogue-model/
https://www.cnbc.com/2026/08/01/open-ai-hugging-face-hack-cyber-warnings.html
https://www.benzinga.com/markets/tech/26/08/60866270/hugging-face-ceo-calls-for-mandatory-disclosure-of-ai-cyberattacks-after-openai-security-incident

Repost this. Thanks.