They want “regulation” but we already have it. Hacking is illegal. Start locking up those responsible for this mess and I assure you they’ll “have a handle on it” quite quickly.
But also, what was the material damage to HuggingFace? AFAICS, it rapidly increased their profile to the point that Jensen claims he paid too much for HF, because he bought right after the hack.
Just contemplating the idea that you're going to be the target of thousands of relentless brute-forcing AI agents till the end of time and that you're too dependent on Big AI to do anything about it would be enough for many people to throw in the towel.
Jensen seems to be whining in order to deflect criticism of the purchase price. I'm more inclined to believe HF warmed to selling after the incident because of the damn-if-you-do-damned-if-you-don't legal quagmire. Nvidia is one of the only entities that would be positioned to able to sue OAI in the future, or compel them to take more preventative measures.
" Our analysis suggests that the recent investments in AI-related categories have contributed significantly to the real GDP growth in 2025. It has surpassed the contribution of IT components to the real GDP growth made during the dot-com boom, both in levels and as a share of GDP. As firms continue integrating AI into their operations and building the infrastructure required to support it, these categories are likely to remain significant drivers of investment well into 2026 and beyond. "
https://www.stlouisfed.org/on-the-economy/2026/jan/tracking-...
If I run over your mailbox maybe we can come to an agreement where you don't sue me, but if I was driving recklessly I've still committed a crime that you cant absolve me from.
It should be the same re: losing control of your agents.
The orange man's influence doesn't extend as far as he thinks.
Remember, the original idea for OpenAI was to make open (thus the name) AI models that could only generate a maximum return of 100x for the investors. There was none of this hyperscaling, proprietary technologies, pure profit motive, etc. until later on.
I think it ultimately comes down to ideology. Simple financial math has nothing to do with it and never has. SV and DC, at least today, have a lot of beliefs in common. It can really be summed up as "divine right of CEOs". These are the "best and brightest" who came from the right parts of the country, who went to the right schools (even if they didn't finish their degrees), and ran in the right circles. They don't simply receive the opportunity to make unfathomable wealth and power; they're owed it. If they do something, by default, it must be right, and if a circumstance comes in their way, it's the circumstance that is wrong.
That's why you don't see a small motorcade of black Chevy Suburbans headed to these companies' headquarters from the local DHS field office. They aren't wrong; the expectation that the AI agent doesn't hack into government websites is wrong.
there's probably better/more likely to succeed avenues to pursue rather than the cfaa
that's not intent, though. that would be negligence.
anyone pursuing this will have a much easier time pursuing negligence causing damage or something along those lines rather than confining themselves to the cfaa's requirements.
it is unclear to me why people want to use the cfaa so badly. not only would it be harder to hold openai responsible, but a shitty cfaa ruling could also bring along some undesired side effects for security researchers, which i would prefer to avoid.
I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products. Squeeze one disgruntled employee or another.
i am unaware of any case where someone was convicted of first degree murder from a drunk driving accident. my searches came up empty as well. are you able to pull one up?
>I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products.
to successfully prosecute a cfaa case, you would have to prove that openai employees intended to hack specifically into huggingface. not that they wanted a PR boost.
i dont get why everyone's got a hard on for prosecuting this as a cfaa case. skip the cfaa case, go for gross or willful negligence + damages. it'll be significantly easier to hold openai accountable that way.
If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts "oopse!"
yes, they look very silly. but that's not how intent works.
openai is being negligent (willfully so, in my opinion). but i have seen no evidence that they intended to specifically hack huggingface. which is the part that the cfaa wants.
again, there are other laws and other ways to hold openai responsible. but the cfaa is a poor choice.
At some point it becomes clear that openai should expect this to happen and so when they keep doing it, it is because they intend it to happen.
When the mobster says "it'd be a shame if something happened to this place" the law recognizes that as a threat due to the mob's history of making such statements before burning places out.
i have been an expert witness on several cfaa cases. the number of times a company is negligent is not a factor when it comes to determining the intent of each charge.
>This is HN thinking law is software.
this is me relying on my experience with these types of cases.
There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was very delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.
https://www.brandonjbroderick.com/new-york/dog-leash-laws-ne...
Plaintiffs seeking damages must show that owners knew or should have known about the dog’s patterns. Past complaints or vet records help build a strong case.
correct, i dont think any boeing exec wanted their planes to crash and then made specific choices with a clear goal of causing them to.
instead, they made negligent choices that led to unintended outcomes.
This would have positive impacts on employees of META, Boeing, Purdue pharma and related, and the AI companies. By positive, I meant that the people whose choices are negatively affect society would actually be punished meaningfully so that they are dissuaded from taking such action. Personal liability needs to be increased as well, and to the best our ability we should ban the sale of director and officer liability insurance.
Repeatedly doing something that results in a specific outcome, even if that outcome is not explicitly specified or requested as the preferred outcome, can still be evidence of intent.
I am not a lawyer, but I seriously doubt the feds could win a CFAA conviction on the Hugging Face fact pattern, even if they wanted to charge it.
CFAA has specific intent requirements, and unlike some laws, negligence does not suffice. The agents can not have legally cognizable intent and it’s unlikely there’s anyone at OpenAI who intended for the hacking to happen (if there was, the case is easy).
Existing laws don’t contemplate AI agents that have independent goals. We need new ones, the existing laws are not remotely sufficient.
Could you explain what your legal strategy would be to overcome the intent requirement of the CFAA? If openAI didn’t intend to hack anything and agents can’t intend to do anything at all, and the CFAA doesn’t permit negligence to stand in for intent, seems to me like the existing law does not cover the situation everyone keeps saying it does.
In the UK, any form of unauthorised access may be prosecuted.
https://www.legislation.gov.uk/ukpga/1990/18/section/3 (1b.)
https://www.legislation.gov.uk/ukpga/1990/18/section/1 (1c.)
I’m told that the UK is a relatively authoritarian country where citizens have no real rights, so perhaps it can be charged anyway, but the plain language of the statute would seem to bar it.
Can you see the ", or with recklessness as to impairing".
Edit: You seem troubled. The UK is not like you describe at all. We do not have ICE running around. Instead, we have the opposite problem.
AI does not have goals. These are statistical models of language patterns that people shape into different tools, and that people direct to do things. If I fire up an OpenAI prompt, and enter no input, it is not going to do anything.
No, someone at OpenAI is running the model with some sort of prompt and allowing it to just follow the numbers to do whatever it wants, up to and including breach of government computer systems.
Whether that means anything to the CFAA prosecution, I don't know. I'm not a lawyer, but the use of language treating these agents like they're something other than tools at the direction of humans is bad.
It's more like me firing off a rifle into the air on the Fourth of July with no regard for where the bullet lands. I knew that it must come down somewhere, but fired anyways.
I don't really see the harm in charging someone under the CFAA. Let's see if a jury agrees with the charge or not. If not, write new laws.
You can try to language-police all you want, that doesn’t change the fact that the best way to describe the reality of the effects that LLMs have on the real world is to use language that analogizes to human concepts.
Ultimately, they do nothing without humans in the loop. The prime mover here is a person who can bear at least some legal consequence for what the program does, even if it's just having to deal with an investigation.
- It's just an Independent Security Researcher.
- So that's it? You will do no action?
- Correct
As Mitt Romney once said “corporations are people.”
[1] Hawaii and Louisiana are strange in this regard. Some other states have a version of this but severely cap the amounts.
[2] "foreseeable" here standing in for a broad set of legal standards that roughly map to negligence/gross negligence/recklessness on the part of the parent
I'm totally on board with treating it as gross negligence requiring hundreds of millions or billions of dollars paid in fines and compensation to victims, but don't act like this is more than what it is.
So, there is a regulatory framework for "safe-ai" that shields these companies from liability. This way, they can sell "safe-ai" to enterprises and if shit-hits-the-fan at the enterprise, sorry, this is certified "safe-ai" so, your bad. Shift blame. From an enterprise buyer's perspective they can say, hey, I bought "safe-ai" and so dont fire me when it "rm -rf"s the production database. Still, it beats me why they are painting their product in a negative light, and scaring their own enterprise customers. After this sort of marketing, any enterprise buyer would be scared to go anywhere near it
1. Wanting a regulatory moat around their products as you said
2. Trying to keep the """AGI""" hype alive. Evil robot hackers is a plausible Al consequence of AGI
In the cases that I have seen covered, the AI just paper clip maximized its way to success. It has no morality / larger motivational structure. It just kept token predicting its way to wards whatever goal it was tasked with.
Model versions which gave up were discarded, leaving the ones that get to success on long horizon tasks.
Just because its a computer program, doesn't mean they can actually make it not go rogue.
Sure you can add more telemetry, have better observation, but there is no fundamental barrier that can be implemented that ensures an AI won't go rogue.
Seems only fair that tech workers get to have their life ruined with 2-3 year prison stints since they feel fine destroying society.
Any AG that starts prosecuting these people will easily win any political race they decide to enter. The environment is too good; voters, rightfully I'll add, despise big tech's leaders and workers.
These AI companies are just skirting basic cybersecurity stewardship.
Stop calling it AI running amok and start labeling what it should properly be called - Gross mismanagement of cybersecurity.
This is one of the many ways the AI industry dies.
Is OpenAI worse at airgap/etc than Anthropic/etc or are its models worse at this rogue behavior?
Do we have special benchmarks for agentic systems going rogue in this manner? Sure it's OpenAI atm.. but it could be my grandmas PC next week. Concerning honestly.
It's beyond me why OpenAI and Anthropic C-levels aren't criminally accountable and/or indicted for these acts of their AIs.
"Humanity still doesn't seem to have a handle on all of its rogue AI activity."
It's been largely harmless thus far and I am fairly sure that OpenAI, etc, have been writing checks to resolve it.
What a detestable institution.
It's also pretty wild that these "AGI" super intelligent systems are too stupid to realize they're potentially causing legal problems. Almost like they're still just fancy auto-complete and not intelligent at all.
Its reasonable to desirie more powerful tools.
You want more capable AI? Awesome. You wan't AI that doesn't throw cyber security false positives? Sure why not. You want the model to run a fleet of agents? Have at it.
But then being surprised that this setup results in autonomous criminal activity at scale? Really? What did people think was going to happen?
The affected companies prefer to forget it and are not going to start a legal fight against the AI industrial complex and potentially the Trump government.
The Government itself thinks the AI labs are too big to fail, and that winning the "AI race" against China is worth anything.
And both labs are basically managed by Effective Altruism cult leaders that think they are ushering the next step of evolution.
Nobody is going to even pretend to give them a symbolic slap on the hands.
Why would they even try to stop what is obviously intentional behavior?
Look at all the podcasts, think pieces, news segments (like this article) that have been generated. Endless hand wringing by pundits, pearl clutching by opinion thinkers, ultimately with focus on OpenAI and how powerful their models are.
All right in the middle of corporate budget season when every C-Suite is looking a a spreadsheet saying “remind me why we’re sending money to these guys again?”