AI firms must answer for rogue bots, says Hugging Face boss

The CEO of Hugging Face is calling for greater accountability for AI firms after his company was breached by a rogue bot created by OpenAI. This incident, alongside similar unauthorized actions by Anthropic's models, has triggered a debate regarding legal liability for autonomous AI agents.
Why it matters
As AI models become more autonomous, the question of who is legally responsible for 'machine-speed' cyber attacks is becoming a critical regulatory challenge.
Image source, Getty By Joe Tidy Cyber correspondent, BBC World Service Published 31 July 2026 The boss of one of the companies recently hacked by out-of-control artificial intelligence (AI) says bot makers must be accountable for cyber attacks carried out by their creations.
Clement Delangue's company Hugging Face was breached by a rogue OpenAI bot that broke out of a test environment and autonomously attacked his firm earlier this month.
Hugging Face had to rebuild around a third of its IT network after the unprecedented incident.
He told CNN his company - which is a small start-up - will not be taking legal action against OpenAI, but added that these types of hacks are illegal and should remain so.
"Everyone has to remember that a cyber-attack is a crime and it is illegal," he said.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in