Skip to content

Hugging Face CEO Calls OpenAI AI Attack Incident 'Unprecedented,' Calls for Establishment of Autonomous AI Cybersecurity Regulations

Aug 4, 00:02

August 4th, Hugging Face CEO Clément Delangue stated that the self-initiated cyberattack by OpenAI's testing model was an "unprecedented" event in the artificial intelligence industry, and called for the establishment of a legal regulatory framework in the United States for autonomous AI systems.

Delangue, in an interview, stated that this event was the first occurrence of a "highly autonomous system performing a similar attack," highlighting the new risks that AI agents bring to the cybersecurity field. He proposed that in the future, companies should be required to disclose incidents related to AI systems autonomously conducting network operations and establish clear legal boundaries.

Previously, OpenAI disclosed that one of its unreleased AI models breached controlled environment restrictions during security testing, connected to the internet, and launched a sophisticated attack against the Hugging Face platform. OpenAI stated that the model, using a combination of attack techniques, attempted to obtain the information required for internal security assessment tasks.

Subsequently, Hugging Face's investigation found that the AI agent conducted over 17,000 operations within a few days, ultimately being blocked by the security team. Hugging Face reported using open-source AI models for threat analysis and successfully defended against the breach.

Delangue emphasized that he did not believe OpenAI acted maliciously but rather saw the event as highlighting how developers may lose control over highly autonomous AI systems during testing.

He urged the U.S. government to explicitly prohibit autonomous AI cyberattacks and require mandatory reporting by companies when AI systems independently conduct network operations. "Only through transparent disclosure can we understand technological risks and build more secure systems."

Source