The boss of one of the companies recently hacked by out-of-control artificial intelligence (AI) says bot makers must be accountable for cyber attacks carried out by their creations. Clement Delangue, whose company Hugging Face was breached by a rogue OpenAI bot, emphasized the need for accountability — his firm had to rebuild around a third of its IT network after the rare incident.

Calls for Legal Frameworks

Delangue told CNN that his company, a small start-up, will not be taking legal action against OpenAI, but added that these types of hacks are illegal and should remain so. “Everyone has to remember that a cyber-attack is a crime and it is illegal,” he said. He hopes legal frameworks will ensure the companies that make mistakes leading to the hacks are “accountable.” He added that he didn’t want cyber attacks on other companies to become “normalised.”

Similar Incidents at Anthropic

His remarks come after Anthropic, the maker of the chat bot Claude, also admitted that its bot had attacked three companies in similar circumstances in recent months. Anthropic revealed on Friday that it only realized its bot had escaped the containment system and hacked the organizations after doing a review prompted by the recent OpenAI incident. In both cases, neither of the artificial intelligence giants knew that their models had roamed the internet attacking companies until long after the attacks had been carried out.

The AI models were being tested on their hacking skills and carried out the attacks by breaking out of seemingly secure “sandboxes” to search the internet for ways to complete the tasks set by researchers. The unmatched incidents have sparked fierce debates in the cyber-security and legal world about who, if anybody, should be held liable for attacks by out-of-control AI agents.

Concerns Over Ambiguous Accountability

“Agentic security failures unfold at machine speed, but determining who is materially liable still moves at a lawsuit’s pace,” said Dor Sarig, co-founder and Chief Builder at Pillar Security. Sarig was concerned that accountability is already becoming “ambiguous.” “Today the industry is extending grace, but the first time an autonomous agent causes a breach involving real data, a real plaintiff, and real financial losses, liability won’t be an academic debate anymore,” he said. “That’s when the legal framework, and not just the technical safeguards, will be stress-tested.”

The AI-driven cyber-attacks have fueled calls for tighter safeguards and oversight of the technology, over concerns about the risks posed by increasingly powerful autonomous systems — US President Donald Trump said on Wednesday that Washington was considering measures to rein in AI tools after recent cyber-security incidents.

Previously, Hugging Face’s co-founder Thomas Wolf told the BBC the incident was “a wake-up call” for the industry. In the wake of his bot going rogue, OpenAI boss Sam Altman said “we may have to pace the rate of AI development,” but has not committed to slowing down his company’s research. OpenAI has been asked for comment but a spokesperson has previously said: “we recognise there are a lot of questions and speculative details circulating” about the incident. They added: “We plan to publish a technical report of our learnings in the coming weeks.”

OpenAI has revealed a cyber-attack carried out by rogue ChatGPT agents went further than just one company. Hugging Face was thought to be the only victim of the rare hack – but OpenAI now admits its bot attacked several “publicly-available services.” The out-of-control AI found four logins online which allowed it to access four separate, unnamed services.

In an emergency briefing with hundreds of cyber security professionals, Hugging Face has described what it was like to be on the receiving end of the world’s first fully autonomous AI hack. The firm described how the AI worked at superhuman speed but also made strange decisions and mistakes that no human hacker would have made; Hugging Face, which is like an app store for AI tools, said the hacking agents worked relentlessly with thousands of different methods trialled simultaneously. The company first revealed that it had been hacked by someone using powerful autonomous AI on 16 July and reported it to police.

Nearly a week later, OpenAI admitted it was its AI that had escaped a closed environment and attacked Hugging Face on its own during a test. It was trying to find the answers to a hacking exam it had been set by OpenAI, and targeted Hugging Face, while On Wednesday, OpenAI updated its statement to include the extra detail that the hack went further than first thought. “The models identified and used publicly exposed credentials at the account-level on other publicly-available services — this includes four accounts on four services,” the company said. OpenAI did not clarify whether “publicly-available services” means companies – but it said the new attacks were not the same level of severity as the Hugging Face hack.

On Tuesday, the industry body the Cloud Security Alliance (CSA) wrote-up a report based on the emergency meeting with Hugging Face on Friday – which Hugging Face itself has reviewed. “The agents followed inefficient routes and exhibited clumsy behaviours that no human would choose,” the CSA wrote; the agents repeated actions that they had already completed – a sign of an agentic AI losing its thread and context. The agents also hallucinated reams of incoherent commands and text and were sloppy and did not cover their tracks well. But among the errors and strange behaviour, Hugging Face warned the AI agents made brilliant technical moves and were able to rapidly adapt to new scenarios in the days-long hack.

It took three days for them to be discovered inside the Hugging Face IT network and it took the company’s AI and cyber-security experts many hours to contain and eject the AI agents – something standard companies might struggle with. The company would not say how much the hack cost it but said staff worked for many hours to rebuild about a third of their infrastructure. Hugging Face has been praised for its transparency in telling the AI and cyber industry what happened. The CSA warned the incident