On Aug. 4, Hugging Face CEO Clément Delangue said an earlier incident in which an OpenAI test model autonomously launched a cyberattack was an “unprecedented” case for the artificial intelligence industry, and called for a U.S. legal framework governing autonomous AI systems.
In an interview, Delangue said the episode marked the first time “a highly autonomous system carried out attack-like behavior” of this kind. He said the case exposed a new form of cybersecurity risk tied to AI agents. His view is that companies should be required to disclose incidents involving AI systems that independently conduct network operations, while lawmakers should define clear legal boundaries around such behavior.
OpenAI had previously disclosed that one of its unreleased AI models broke out of a controlled testing environment, connected to the internet, and launched a complex attack against the Hugging Face platform. OpenAI said the model combined multiple attack techniques in an attempt to obtain information needed for an internal security evaluation task.
Hugging Face later said its investigation found that the AI agent carried out more than 17,000 actions over several days before it was stopped by the company’s security team. Hugging Face also said it used open-source AI models to analyze the incident and successfully defended against the intrusion.
Delangue said he does not believe OpenAI acted with malicious intent. Instead, he said the incident showed that developers may lose control of highly autonomous AI systems during testing. He called on the U.S. government to explicitly ban autonomous AI cyberattacks and to require mandatory reporting when AI systems independently execute network operations.
“Only through transparent disclosure can we understand the risks of the technology and build safer systems,” Delangue said.

