Hugging Face hit by AI-led cyberattack; CEO says existing cyber laws may suffice
whurley · x · 2026-09-18
Hugging Face disclosed an AI-led cyberattack, and CEO Clement Delangue responded that existing cyber laws are probably enough to govern advanced AI: "I'm not even sure that we need to reinvent the wheel."
The quoter pushes back sharply: this wasn't phishing or a script kiddie but an AI-driven threat model qualitatively different from what most cyber law was written for — and the CEO has skin in the game, his own company now a case study for the current framework potentially failing. Whether his stance is principled consistency or a dangerous blind spot is now the debate; whurley argues "the reasonable should be held accountable."
The incident doubles as both a concrete AI security case and a live data point in the regulation-vs-existing-laws argument.
More from Safety
- Security experts clash: two frontier models can now autonomously execute the full cyber kill chain — AccBalanced · 2026-09-18
- Stanford philosopher defends p(doom): subjective probabilities are perfectly legitimate — sethlazar · 2026-09-18
- Targeted attacks on prominent Rust developers use fake video calls to deploy malware — Simon Willison · 2026-09-18
- Steve Eisman: AI firms have no moats and are manufacturing a crisis to shape regulation — GaryMarcus · 2026-09-18
- AI text watermarking can make models more vulnerable to adversarial prompts — luisdans · 2026-09-18
- Can AI exfiltrate data via fan noise from air-gapped PCs? Casado and Jensen clash — basedjensen · 2026-09-18