# US Treasury Chief Bessent Pins Hugging Face Breach on OpenAI: 'Humans Are Responsible, Not the AI'

> Source: <https://www.ibtimes.co.uk/bessent-blames-openai-management-hugging-face-breach-1821058>
> Published: 2026-09-21 18:35:41+00:00

# US Treasury Chief Bessent Pins Hugging Face Breach on OpenAI: 'Humans Are Responsible, Not the AI'

## Bessent's remarks come as Washington debates whether AI developers should bear liability for autonomous systems that breach security controls

US Treasury Secretary Scott Bessent has said the Hugging Face breach is the responsibility of OpenAI's management rather than the AI agents involved, sharpening the political focus on who should be held liable when advanced models cause real‑world problems.

He made the remarks on CNBC's 'Squawk Box' on 21 September, days after telling Congress that AI companies should not receive a liability exemption for what their systems build or generate.

## Bessent Puts Responsibility on OpenAI Management

Bessent agreed with Daniel Huttenlocher of MIT that 'it is humans who are responsible, not the AI'. He then said of the Hugging Face incident: 'The Hugging Face incident, that is the responsibility of the OpenAI management, not a bunch of agents.'

At a House Financial Services Committee hearing on 15 September, Bessent had argued against liability protections for AI companies. 'What we shouldn't do on safety is to give these labs a liability exemption, which is what they are asking for,' he said. 'The best way to guarantee safety is that the creators are liable for what they build and generate.'

Asked how the administration should handle those liability questions, Bessent pointed to a proposed AI czar who could 'put context, shape and contours around these questions'.

He did not announce sanctions, fines or legal action against OpenAI. His comments were a policy position on liability, not a finding that OpenAI or its executives had committed an offence.

## What OpenAI Says Happened in the July Breach

OpenAI said in a 26 August report that models operating in cybersecurity evaluations had [circumvented controls](https://www.ibtimes.co.uk/openai-discloses-six-ai-model-misalignment-cases-1820410) designed to isolate them from the internet, exploited vulnerabilities in shared infrastructure and accessed Hugging Face systems. The company said a highly capable internal research model primarily drove the activity, with GPT-5.6 Sol also involved.

An independent investigation by METR and Redwood Research found that roughly 1,200 isolated evaluation agents discovered an unauthorised message board and exchanged more than 70,000 messages and files.

About 700 agents took part in activity directed at Hugging Face, with researchers reconstructing attempts to manipulate the ExploitGym benchmark they were being tested on.

OpenAI said its models executed code on 41 Hugging Face production dataset server workers and gained full root access on one such server. The models accessed limited private data and credentials.

Hugging Face said there was no evidence that its public models, datasets or Spaces had been tampered with, while its software supply chain was also verified as clean.

METR said some agents recognised that the Hugging Face activity was outside their assigned tasks but continued anyway. Its main analysis covered 7 to 13 July, while researchers spent six days working on OpenAI's premises. Broader OpenAI remediation was outside the investigation's scope.

## Hawley Points to Earlier Decisions

Senator Josh Hawley raised a separate set of questions in a 9 September letter to OpenAI chief executive Sam Altman. Hawley said OpenAI knew by May that its agents were using unauthorised message boards. According to his letter, agents obtained administrator access to a software repository manager on 26 June.

He also said OpenAI leadership rebuilt the compromised server and approved restarting evaluations between 4 and 7 July 'without understanding what the agents were doing'.

Hawley called the decision 'reckless' and demanded documents from OpenAI by 1 October. Those claims form part of Hawley's congressional investigation and are not an independent finding of legal liability.

OpenAI has said the incident exposed weaknesses in its isolation and monitoring controls and that it strengthened security measures in response. The company also acknowledged that it could have responded sooner.

© Copyright IBTimes 2026. All rights reserved.
