Hugging Face CEO says AI companies should be required to disclose hacks after OpenAI breach

Aug 03, 2026 01:52 PM - 5 hours ago 1

Hugging Face CEO

Hugging Face CEO says we request much openness successful the AI organization to forestall early attacks. Bloomberg/Getty Images

We request compulsory disclosures for AI cyberattacks, says the CEO of Hugging Face.

In an question and reply pinch CBS aired connected Sunday, Clem Delangue said that preventing releases of powerful AI models is not the measurement to extremity attacks for illustration the OpenAI hack connected Hugging Face.

"These problems happened connected unreleased models. So I deliberation the problem is not truthful overmuch limiting the advancement aliases preventing companies from releasing these models," he said. "It's really the opposite. It's giving entree to much group truthful that they tin take sides themselves."

Late past month, Hugging Face, an open-source AI platform, said that it had knowledgeable a information breach successful which an AI supplier had accessed immoderate of its systems. OpenAI disclosed that 2 of its models, including 1 unreleased model, escaped a trial situation and were responsible for the rogue hack.

Last week, Anthropic disclosed a akin incident, saying that it recovered 3 cases of Claude models gaining unauthorized access to different organizations' systems.

During the CBS appearance, Delangue called for "mandatory disclosures of supplier cyberattacks," saying that transparency is needed truthful everyone tin study astir and forestall incidents for illustration this.

"For these cyber attacks, we should beryllium capable to spot what we telephone the supplier traces, which is fundamentally what the engineers asked the agents, and past what steps the agents took to understand if it was a quality mistake, if it was a strategy mistake, if it was an AI mistake," he said.

He added that it is important that cyberattacks stay forbidden nether US law, truthful location isn't an "explosion of them successful the future."

There is presently nary national AI incident reporting rule successful the US. Researchers astatine US deliberation tanks, including RAND and Georgetown's Center for Security and Emerging Technology, person projected a mandatory AI incident-reporting system, arsenic Delangue did.

In June, Texas Rep. Nathaniel Moran projected a measure that would require AI exemplary companies to study information breaches to the US ​Commerce Department wrong 7 days of discovering an incident.

Chinese heroes

The OpenAI-Hugging Face incident gave supporters of the open-source exemplary organization a large win. Open-source models are those whose architecture and training codification are free for anyone to usage aliases modify.

The institution said it utilized GLM 5.2, an open-source exemplary from Beijing-based Z.ai, to analyse much than 17,000 logs and protect itself from the OpenAI attack.

"We defended ourselves pinch an unfastened model, right? Like we couldn't person done it pinch an API because they had these guardrails," Delangue said, referring to really companies entree models complete the internet. "That's 1 illustration of things that we tin beforehand that is going to make the world safer."

In response to the OpenAI incident, LinkedIn laminitis Reid Hoffman besides touted really open-source models tin thief successful specified breaches.

"Agents are an evident solution to this problem," the billionaire wrote successful an X station past month. "Take OpenAI's caller breach; Because OpenAI models don't let precocious cyber capabilities, HuggingFace utilized a Chinese unfastened exemplary (Z.ai's GLM 5.2) to incorporate the rogue OpenAI agent."

OpenAI and Hugging Face did not instantly respond to requests for remark from Business Insider.

Read next

Business Insider

Follow Following

Every clip publishes a story, you’ll get an alert consecutive to your inbox!

Look retired for an alert successful your inbox the adjacent clip publishes a story!

Every clip a caller communicative is published, you’ll get an alert consecutive to your inbox!

Look retired for an alert successful your inbox the adjacent clip a caller communicative is published!

By clicking “Sign up”, you work together to person emails from Business Insider. In addition, you judge Insider’s Terms of Service and Privacy Policy.

More stories by More stories from

More