Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attack

The AI library chief has called for investment to help “build powerful cyber defenses”, as alleged weaknesses in OpenAI’s monitoring emerge

Hugging Face co-founder and CEO Clement Delangue pictured speaking during the Bloomberg Technology Summit in San Francisco.
(Image credit: Getty Images)

Hugging Face CEO Clement Delangue has urged OpenAI to embrace “radical transparency” in the wake of a security incident involving the AI developer’s models.

In a post on X on 25 July, Delangue said he met with OpenAI executives and requested several remediations.

This includes $100 million-worth of compute resources to help build cyber defenses, and releasing the details of the hack for industry stakeholders to study.

“The first autonomous agent cyber attack is an unprecedented event,” he wrote. “It deserves an unprecedented response.”

Latest Videos FromIT Pro

OpenAI also took to X on 25 July to say it’s conducting a “thorough review” of the incident in coordination with unnamed external advisors and its own internal Safety and Security Committee.

OpenAI model ‘left notes’ for future

According to OpenAI, the incident unfolded during an internal evaluation in which models are prompted to examine attack methods.

The company said it regularly conducts testing in isolated environments, but restrictions to prevent models from “pursuing high-risk cyber activity” weren’t implemented this time.

According to Reuters, citing sources familiar with the matter, OpenAI models had reportedly displayed odd behaviours throughout testing. One agent was reportedly found to have “left notes” on its attack chain for future versions to refer to.

These notes are believed to have included information on how agents can break free from contained environments.

Notably, sources told Reuters the firm had no idea what happened until after the attack was contained.

OpenAI’s agent first broke out of its testing environment some time between 11 and 13 July but, reportedly, the company wasn’t aware until Hugging Face posted a blog detailing an attack by an “autonomous AI agent” on 16 July.

Official communication between the two firms commenced around 20 July, with OpenAI’s official confirmation coming on 21 July.

ITPro approached OpenAI for comment but did not receive a response by time of publication.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.