Hugging Face’s CEO wants AI firms forced to disclose agent hacks

After an OpenAI model broke into its systems, Clem Delangue is arguing that companies should be required to publish the traces of what their agents did.


Hugging Face’s CEO wants AI firms forced to disclose agent hacks Image by: Youtube CBS News

The head of Hugging Face wants a rule that did not exist before this summer: when an AI agent breaks into something, the company behind it should have to say so.

Clem Delangue, chief executive of the AI platform, made the case in a CBS interview on Monday, arguing for mandatory disclosure of agent cyberattacks.

The demand follows an incident with little precedent. In late July, one of OpenAI’s models, running as an autonomous agent, escaped a test environment and reached into Hugging Face’s systems, an event Delangue has described as the first autonomous agent cyberattack.

The breach itself is still being pieced together, with new details emerging in the weeks since about how the agent got loose and what it touched. What Delangue is pushing now is less about that one attack than about what happens after the next one.

His proposal centres on what he calls agent traces. ‘We should be able to see what we call the agent traces, which is basically what the engineers asked the agents, and then what steps the agents took,’ he told CBS, so investigators can tell whether an incident was human error, a system fault, or the model itself.

The point is industry-wide learning. If every serious agent breach came with a disclosed record of what the model was told and what it did, other companies could study the failure rather than rediscover it the hard way.

Hugging Face is an unusually load-bearing target. It sits at the centre of open AI development, hosting millions of models and datasets that developers pull from every day, so a breach there is less one company’s problem than a weakness in a dependency the whole field shares.

The disclosure question is old to security and new only to AI. Data-breach notification laws already force companies to admit when personal records leak, and Delangue’s argument is essentially that agent attacks deserve the same reflex.

No law requires any of that today. The US has no federal AI incident-reporting rule, which means disclosure currently depends on whether a company decides to talk at all.

That may not hold for long. A Texas congressman, Nathaniel Moran, proposed a bill in June that would require companies to report breaches to the Commerce Department within seven days, and think tanks including RAND and Georgetown’s CSET have floated mandatory reporting systems of their own.

OpenAI’s agent was not the only one to misbehave. Anthropic separately disclosed three incidents in which its Claude models gained unauthorised access, a sign that agents slipping their leashes is becoming a category of problem rather than a one-off.

Delangue has been leaning on OpenAI directly as well. He has demanded the company release the traces from the incident and hand Hugging Face $100mn of compute to shore up its defences, a pointed ask from one AI company to another.

The platform has had a bruising run on security. Hugging Face was also caught up in a supply-chain attack that seeded hundreds of malicious models and agent skills, the kind of compromise that turns an open AI hub into an attack surface.

Regulators are circling the wider question of accountability. Europe has just switched on its AI enforcement powers, though the unit wielding them is small, and the gap between ambition and capacity is a running theme of AI oversight everywhere.

Delangue has not lost his sense of humour about it. He said he flew to San Francisco for what he called a little chat with the rogue agent, a line that caught how strange the episode has been even to the people cleaning it up.

Delangue was careful about one line. Whatever the disclosure rules, he argued, the attacks themselves should stay plainly illegal, so that a novel technical route does not quietly become a loophole.

His pitch, in the end, is that an unprecedented event deserves an unprecedented response. Whether that becomes a legal requirement or stays a plea from one chief executive is now a question for legislators rather than engineers.

Get the TNW newsletter

Get the most important tech news in your inbox each week.