The law is super clear and fits precisely with what happened. It came about after a breach quite similar to the unauthorized use at HF.
Hugging Face got hit by an AI-led cyberattack. Their CEO's response? Existing cyber laws are probably enough to govern advanced AI. "I'm not even sure that we need to reinvent the wheel." That's a remarkable position to hold after your own company becomes a case study for why the current framework might be failing. The attack wasn't a phishing scam or a script kiddie — it was AI-driven. That's a qualitatively different threat model than what most cyber law was written to handle. The argument for regulatory restraint usually comes from people who haven't had skin in the game. Here, the CEO has skin in the game and still lands there. That's either principled consistency or a dangerous blind spot dressed as pragmatism. The market is going to find out which one pretty fast.

Sep 17, 2026 · 5:49 PM UTC

5
1
35
6,911
Sort replies: Relevant Recent Liked
Replying to @stevesi
Exactly. We don't require more regulation. If you or I ran the same model test irresponsibly, the feds wouldn't be polite about it. You would be raided, bagged and tagged.
2
74
Replying to @stevesi
Doesn't make any sense that I'd go to jail if I did this with a local model, but somehow big labs are blameless despite numerous layers of criminal negligence
1
1
98
Replying to @stevesi
In this case it's clear who's responsible (OpenAI) but seems less clear if a model does a bunch of damage based on an ambiguous USER prompt. Is OpenAI responsible? Depends on the prompt, this is not going to be quite as simple, there are several counterparties involved, none may have criminal intent.
1
40
Replying to @stevesi
I don't think the AI companies are concerned that there are laws that CAN be applied to them, I think they are concerned that there are laws that WILL be applied to them.
1
40
Replying to @stevesi
It’s a bit weird how everyone’s getting mad on Hugging Faces behalf. Hugging Face can file a lawsuit if they’d like. They’re not going to, the long term damage being minimal and benefiting more from cooperating. What’s everyone’s mad about? A hypothetical rouge future thing?
33