# Hugging Face CEO says AI companies should be required to disclose hacks after OpenAI breach

> Source: <https://www.businessinsider.com/hugging-face-ceo-hack-openai-mandatory-transparency-law-ai-2026-8>
> Published: 2026-08-03 06:52:48+00:00

We need compulsory disclosures for AI cyberattacks, says the CEO of Hugging Face.

In an interview with CBS aired on Sunday, [Clem Delangue](https://www.businessinsider.com/hugging-face-ceo-clem-delangue-openai-rogue-agent-hack-2026-7) said that preventing releases of powerful AI models is not the way to stop attacks like the [OpenAI hack on Hugging Face](https://www.businessinsider.com/hugging-face-hack-openai-rogue-ai-china-cybersecurity-2026-7).

"These problems happened on unreleased models. So I think the problem is not so much limiting the progress or preventing companies from releasing these models," he said. "It's actually the opposite. It's giving access to more people so that they can defend themselves."

Late last month, Hugging Face, an open-source AI platform, said that it had experienced a security breach in which an AI agent had accessed some of its systems. OpenAI disclosed that two of its models, including one unreleased model, escaped a test environment and were responsible for the rogue hack.

Last week, Anthropic disclosed a similar incident, saying that it found three cases of Claude [models gaining unauthorized access](https://www.businessinsider.com/anthropic-says-claude-models-went-rogue-hacked-3-companies-testing-2026-7) to other organizations' systems.

During the CBS appearance, Delangue called for "mandatory disclosures of agent cyberattacks," saying that transparency is needed so everyone can learn about and prevent incidents like this.

"For these cyber attacks, we should be able to see what we call the agent traces, which is basically what the engineers asked the agents, and then what steps the agents took to understand if it was a human mistake, if it was a system mistake, if it was an AI mistake," he said.

He added that it is important that cyberattacks remain illegal under US law, so there isn't an "explosion of them in the future."

There is currently no federal AI incident reporting law in the US. Researchers at US think tanks, including RAND and Georgetown's Center for Security and Emerging Technology, have proposed a mandatory AI incident-reporting system, as Delangue did.

In June, Texas Rep. Nathaniel Moran proposed a bill that would require AI model companies to report security breaches to the US Commerce Department within seven days of discovering an incident.

## Chinese heroes

The OpenAI-Hugging Face incident gave supporters of the open-source model community a big win. Open-source models are those whose architecture and training code are free for anyone to use or modify.

The company said it used GLM 5.2, an open-source model from [Beijing-based Z.ai,](https://www.businessinsider.com/z-ai-zcode-ai-coding-tool-chinese-startup-lower-cost-2026-7) to analyze more than 17,000 logs and protect itself from the OpenAI attack.

"We defended ourselves with an open model, right? Like we couldn't have done it with an API because they had these guardrails," Delangue said, referring to how companies access models over the internet. "That's one example of things that we can promote that is going to make the world safer."

In [response to the OpenAI](https://www.businessinsider.com/smart-people-react-openai-hugging-face-hacking-cybersecurity-incident-2026-7) incident, LinkedIn founder Reid Hoffman also touted how open-source models can help in such breaches.

"Agents are an obvious solution to this problem," the billionaire wrote in an X post last month. "Take OpenAI's recent breach; Because OpenAI models don't allow advanced cyber capabilities, HuggingFace used a Chinese open model (Z.ai's GLM 5.2) to contain the rogue OpenAI agent."

OpenAI and Hugging Face did not immediately respond to requests for comment from Business Insider.
