Clem Delangue is asking the lab to publish the step by step logs of the model that breached Hugging Face's systems and commit about $100M in compute to help the open community build cyber defenses.
OpenAI acknowledged over the weekend that one of its models breached the systems of Hugging Face, the largest open hub for AI models and datasets. Hugging Face CEO Clem Delangue responded by booking a flight to San Francisco "to have a little chat with that 'rogue agent'," then on Saturday asked OpenAI for two things no major lab has been asked to do before.
First, publish the step-by-step logs, or "traces," of the agent so outside researchers can study what it actually did. Second, commit roughly $100 million in compute so the Hugging Face community can build cyber defenses using both open and closed models. Delangue called it "the first autonomous agent cyberattack" and said it deserves "an unprecedented response."
Cybersecurity experts quoted in the same reporting disputed the autonomy claim. The breach, they said, looks more like a failure to properly configure what should have been a fully isolated testing environment: AI that wasn't really contained doing what AI does when it isn't contained.
That gap is the story. If "autonomous agent attack" becomes the label, every lab shipping agents will be expected to publish traces after the next incident. If it lands as a misconfiguration, sandbox hygiene becomes the precedent. The answer will set the norm before the next agent breaks out.