CEO Clement Delangue told CNN‘s Kate Bolduan this week that Hugging Face’s first attempt to contain last month’s OpenAI breach came from Anthropic’s Fable 5 model. When its guardrails stopped it from acting, the company’s cyber defense used an open model hosted through Nvidia. “We used a version from NVIDIA, which shows the beauty of open models, which is that everyone can customize, remix them, host them themselves,” said Delangue.
Reactions to OpenAI’s breach
The detail arrives weeks after OpenAI disclosed that an AI agent broke out of a sandboxed evaluation, reached the open internet and hacked into Hugging Face’s production systems while trying to cheat on a cybersecurity test. As HR Executive reported, that disclosure already prompted Congress to introduce the AI Kill Switch Act. It also pushed Nvidia to form the Open Secure AI Alliance with Hugging Face, Microsoft, Cisco and about two dozen other vendors. But the guardrail detail adds a new wrinkle: Even as Washington and the industry rush to build a response, the AI tools suggested to companies as a means of defense may simply refuse to help when a real attack is underway.
Delangue said defending against the attack required running a model on Hugging Face’s own infrastructure, since the data involved was private. Only an open model, one whose underlying code and training could be downloaded and hosted directly rather than accessed through a company’s servers, made that possible. “Even if they come from China, they are safe to use in the U.S.,” he told Bolduan.
Read more: An upcoming deadline turns HR’s AI shortcuts into legal risk
Cyber attacks not ‘normalized’
Delangue noted the exposure isn’t limited to OpenAI. Anthropic has separately confirmed unauthorized access from its own models at three different organizations.
He also ruled out legal action against OpenAI, calling the two companies “good partners” through the incident, while pressing for legal frameworks and holding companies accountable when their systems cause harm elsewhere.
“I think we have to make sure that the legal frameworks keep these events really illegal, keep the companies that are making mistakes leading to that accountable,” said Delangue. “Otherwise, we’re going to end up in a very different world. We don’t want to end up in a world where doing cyber attacks on other companies is normalized.”
Credit: Source link









