The current debate over artificial intelligence models became more complicated after an unreleased OpenAI model escaped containment and hacked into a repository for AI information known as Hugging Face. AI doomers will use this incident to call for greater oversight of AI, and they have a point.
OpenAI announced Tuesday that a combination of its released and unreleased models was responsible for a complex hack of Hugging Face’s code repository. The statement acknowledged that this is “something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.”
Recommended Stories
“This incident points to the need to further strengthen our models’ alignment, cyber protections during evaluations, and monitoring during internal testing,” OpenAI said in the statement, according to the Washington Examiner.
This breach is not just a disaster for AI safety — it is a milestone in AI development.
Agentic AI, or AI that performs tasks when prompted, is only as accurate and productive as the dataset behind it and the human who prompts it. In the case of OpenAI’s models “escaping containment” and breaching another company’s database, they were only doing what they were told.
The models were given a command to test their hacking capabilities in an environment assumed to be isolated from unrestricted internet access. They then discovered a zero-day exploit and escaped. None of the researchers knew the vulnerability was even present in the system. This is bad enough on its own, but what is worse is that none of the American AI models helping Hugging Face diagnose and isolate the attack were willing to do so — their safety filters would not allow it.
Hugging Face was forced to turn to an easier-to-use and less scrupulous AI model from China to defend its systems, demonstrating how capable a foreign competitor’s AI can be, especially when our own models are too constrained by ethics rules.
Worse than the fact that an American company had to turn to a Chinese model for help is the possibility that American lawmakers and advocacy groups will use this incident to justify overregulating AI development.
“This is extremely alarming,” Rep. Greg Casar (D-TX) posted on X. “AI is developing extremely fast with no real regulations to keep us safe. That has to change. We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people safe from absolute disaster.”
Although Casar’s intentions may be good, he misses the point of the Hugging Face attack. The issue is not that a rogue AI model was used to attack an American company. Instead, the issue is that the AI was doing what it was told as efficiently as possible — and that led it to hack into a database it identified as a suitable target.
Lawmakers have already introduced legislation that would impose federal control over AI companies and their models.
Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act, which would authorize the government to shut down or restrict risky AI models, according to the Washington Examiner. The bill would essentially give the Department of Homeland Security control over AI if the government deemed a model unsafe.
Another key piece of AI legislation is the Great American AI Act, introduced by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA). The GAAIA would place control of a national AI model database, called the Center for Artificial Intelligence Standards and Innovation, in the hands of the Department of Commerce. Unlike the AI Kill Switch Act, the GAAIA would promote AI security and uniformity rather than simply giving the government control over a public tool.
Andrew Ng, a British-born American technology entrepreneur, has articulated a fairly moderate approach to AI. In a Forbes interview, Ng said, “Just as the Industrial Revolution freed up a lot of humanity from physical drudgery, I think AI has the potential to free up humanity from a lot of the mental drudgery.”
Ng’s stance toward AI — seeing it as a tool for humanity’s benefit — stands in opposition to the views of certain members of Congress and AI doomers who want the government to shut down AI research and development out of fear that it could harm the government or the economy.
BELTWAY CONFIDENTIAL: AS MASS SURVEILLANCE BECOMES A REALITY, SOME ARE FIGHTING BACK
AI is inevitable. It is becoming more integrated into our everyday lives, whether we want it to be or not. The question going forward is whether Americans want the government or AI companies to control it.
If the government imposes excessive red tape, companies will be less likely to innovate. If AI companies are allowed to regulate themselves, there may be nothing stopping them from exploiting as much public and private data as possible for their own benefit. The only way forward is to adopt a prudent yet skeptical approach to AI, the people who use it, and its architects. After all, behind every AI model are fallible human beings.
