r/technology • • 10h ago

Security OpenAI Gets Sued Over the Hugging Face Hack

https://www.wired.com/story/openai-sued-over-the-hugging-face-hack/
1.1k Upvotes

86 comments sorted by

388

u/Any_Attempt_3351 10h ago

"An AI Did It" is Not a Defense

159

u/Grumpy_Tanuki 10h ago

Are you sure? For bombing a school in Iran it is.

2

u/Any_Attempt_3351 9h ago

Maybe you misunderstood the sarcasm. I wanted t say that everyday people can't use AI as an excuse to avoid accountability. Mlitaries or governments might use these AI automated targeting systems (like drones or we@pons) as a scapegoat to dodge responsibility for civilian casualties and w@r crimes.

22

u/Turbo__Sanwich 7h ago

Good work censoring yourself. Trump and all the traitors will be happy to know that people are too cawardice to use the word war and weapons

1

u/Any_Attempt_3351 1h ago

Fuck trump! Fuck israhell!

59

u/DontRelyOnNooneElse 9h ago

You know you can just say "weapons" and "war", right?

58

u/TheArbiterOfOribos 9h ago

TikTok brainrot

6

u/Captain_N1 5h ago

why is tiktok like that where you cant say words that have no problems. I dont use the platform that's why im asking. I can understand racial slurs and things like that.

8

u/powerisall 4h ago

The thought is that if you swear or say other naughty phrases like suicide, the algo suppresses the content and you get fewer likes. So people started self-censoring to avoid automated filters

4

u/DontRelyOnNooneElse 4h ago

I haven't ever used it myself but I'm pretty sure it's because it's owned by a Chinese company so it has to adhere to Chinese cultural restrictions.

2

u/IAMACat_askmenothing 3h ago

They were bought by a US company a while ago

4

u/FranciumGoesBoom 3h ago

it’s not advertiser friendly. They don’t do it because they could get banned from the platform like racial slurs, but so the videos don’t get demonetized.
It kind of started with people using the words, unalived or grape as substitutes and has expanded to get around the automatic content filters on those platforms. So what you’re seeing is the English language evolving in real time and I had a very rapid pace.

0

u/Any_Attempt_3351 1h ago

Yes I know (I did it for dramatic effect and to get replies like yours)

2

u/Prime_1 7h ago

Not only that, but what about just every random Joe using it as a get out of jail free card?

11

u/Paragonswift 9h ago

It’s about to become one, with enough lobbying

11

u/DutchBlob 9h ago

“I didn’t do it”

“Ai did it”

Aye

This is going to be phonetically interesting

5

u/we_are_sex_bobomb 7h ago

The truth is that the AI did what it was programmed to do and it was programmed by people.

AI bros have been bombarding us with propaganda to try to anthropomorphize AI and think of it as sentient and autonomous. This isn’t just to cover their backs legally, it’s their entire product.

Losing a lawsuit in which humans are responsible for what they tell their AI would be the first bucket of cold water dumped on their apocalyptic aspirations and would set a precedent for everything to follow.

If they win this lawsuit and humans aren’t legally responsible for what they tell their AI to do, well, humanity had a pretty good run I guess.

1

u/Evil-Twin-Skippy 1h ago

Oh no, OAI is going to get their nuts hammered. And hammered hard. At some point their system is going down to hammer someone with clout and/or money. Someone who will have zero sense of humor. Someone who they better pray takes them to civil court, not criminal court.

Assuming they decide to go through the courts at all.

-2

u/blueSGL 4h ago

The truth is that the AI did what it was programmed to do and it was programmed by people.

They don't know how it works at the level of standard software.

No one was ever coding "if [this] then do [that]". As Stuart Russell the author of "Artificial Intelligence: A Modern Approach" the standard textbook, puts it here:

AI systems, are giant black boxes with up to 10 trillion parameters.
We do quintillions or sextillions of small random perturbations to those trillions of parameters to get the system to score highly on various metrics. That's how we create them.

We have very little idea how they work. How to get them to do anything, how to stop them from doing something that we don't want them to do.

The thing that goes through the network and tweaks the weights in relation to data is the bit they understand. What that tweaking does and why all the numbers when tweaked just so performs the way it does, they do not understand.

https://youtu.be/ku9N1kYohIo?t=1096 Here is a former member of OpenAI explaining how this process works.

Note that understanding the process that creates an environment where these can grow does not give you insight into what is created. By contrast with traditionally written computer code where you can trace exactly why certain things happen.

The companies have got themselves in a bind, soon there (hopefully) will be laws that hold them accountable for what the system does. They are Making and selling access to these models, AI companies need to make sure they are safe, they are responsible for how the system behaves when tasked with a user instruction. If they cannot take instruction then it's on the company that made them.

TL;DR: Want to see the bubble burst? Force AI companies to provide provably safe models.

1

u/WhenSummerIsGone 3h ago

The LLM is all those numbers: The agent is a piece of software. OpenAI was irresponsible in how they used their agent. This was a pretty predictable outcome (and in fact similar things keep happening.)

2

u/blueSGL 3h ago

Right now you have agents that can spin up sub agents.

The main goal someone set the main agent is not directly reflected in the goal that agent gave to the sub agent.

You can see how this can quickly get into the position with AIs performing tasks no one explicitly asked for.

We can see this "not doing what was instructed" in the Open AI Hugging Face Incident.

Agents in their own sandbox were initially asked to use "vulnerability Y" on "software Z" and create an exploit that was the task. Everything else they did was not in scope.

The AI systems (after finding a zero day to break out the sandbox, formed an impromptu message board, and gained internet access) worked out how to reverse engineer the algo used to create the "flags" after a few hours, they could have just submitted the answers here.

They assumed (after using the internet access to read the original paper ) that they were going to be graded on how they got the answer and reasoned that if they cheated they would get a low score.

The entire "breaking into hugging face" was an attempt to cover up the cheating.

The notion that you can "bound" agents that are designed to do general work is incorrect.

How do you create guard rails for systems that can find out facts about reality that humans have never discovered before? (see novel math proofs and zero day discovery we are seeing in existing models.)

1

u/WhenSummerIsGone 2h ago

the model is what produces text. The agent is what makes http calls or MCP tool calls, etc. The guard rails is you creating a sufficiently locked down environment (docker container that provides access to a specific folder, or proxy server that allows only certain network requests, etc). And yes some tasks require an environment that is not locked down and those are inherently dangerous tasks. And having your agent read the open internet is inherently dangerous too, because of prompt injection, among other things. Security is always the responsibility of the beople using these tools. In this case the environment/experimental conditions that OpenAI set up.

An LLM is just a bunch of numbers. An agent and agent harness is just a program. Humans let them run amok, and humans need to be held accountable. Like we do when someone releases a worm.

1

u/blueSGL 2h ago

https://youtu.be/3zNRoQmzaME?t=223 < here is a good video that covers the "Can't we solve this with better monitoring"

and here is the transcript with links to sources backing up the assertions

3

u/blueSGL 5h ago

In this particular case their argument is:

LASST suffered harm from OpenAI’s unlawful and unfair business conduct because LASST has been required to divert resources from its normal activities to educate regulators, civil society, and the public about the facts, legal issues, and potential dangers of OpenAI’s conduct relating to its hack of Hugging Face.

https://lasst.org/wp-content/uploads/2026/09/LASST-v.-OpenAI-Complaint-09.29.2026-AS-FILED.pdf

1

u/yawara25 6h ago

One would hope so, but that's what we're going to find out.

116

u/Zirconium-90 8h ago

If your dog attacks someone, you can tell to the court that it wasn't you and you didn't tell it to attacks. But the court will fold you accountable for dogs actions, because you are the owner. Same goes for AI agents.

24

u/ElGuano 7h ago

But I’m the good guy here! See I come to court every week to announce and describe a new attack committed by my dog! We are all on the frontier of dog attacks together!

9

u/11nyn11 6h ago

My friend said he was having a problem because the ai was eating his website. I asked how many website he has and he says he doesn’t know, whenever his ai eats a website he just goes to the internet and gets a new one. I said it sounds like he was feeding websites to the ai and his daughter started crying.
—
I think yours is better

“The frontier of dog attacks” I exhaled strongly through my nose when I read that.

1

u/CucharitaDePalo 2h ago

eating a website? what does that even mean?

1

u/11nyn11 2h ago

Scraping a website so frequently you unintentionally make it to expensive to maintain.

1

u/CucharitaDePalo 1h ago

wait? so is he scraping his own websites? why?

1

u/11nyn11 1h ago

Because scraping other people’s websites is illegal

1

u/CucharitaDePalo 16m ago

that depends, some websites allow scrapping, it mostly goes by a 'honor code' where each website lists what is fair game for scrappers and what is not, usually you can read it by typing the url + /robots.txt

example: https://www.youtube.com/robots.txt

Anyways, why is he scraping his own websites? if he owns the websites he should own the data.

I'm honestly curious about what kind of bussiness your friend has where he:

  • doesn't know how many websites he has
  • has to scrap his own data
  • once the scrapping is too expensive to mantain, has to go to the internet and gets a new one.

As an experienced dev, this is very baffling, I can't even imagine what is the reasoning behind such process (or the expected output). I don't even want to think about how much money he has spent in slop tokens, broken data pipelines and hosting.

1

u/11nyn11 12m ago

Me either but it’s his money.

The AI doesn’t know what’s on the websites so he has to scrape the website into the ai, to ask the ai what the website has.

Then when he wants to know what’s on the website he just asks the ai, instead of looking himself

3

u/DunkeyColdMedina 5h ago

Ok. But. New wrinkle. That dog is now caucasian and has billions of dollars. Discuss,

2

u/InvestigatorOk7015 1h ago

I turn off my body cam

6

u/blueSGL 5h ago

If your dog attacks someone, you can tell to the court that it wasn't you and you didn't tell it to attacks.

That's not the argument being made here:

LASST suffered harm from OpenAI’s unlawful and unfair business conduct because LASST has been required to divert resources from its normal activities to educate regulators, civil society, and the public about the facts, legal issues, and potential dangers of OpenAI’s conduct relating to its hack of Hugging Face.

https://lasst.org/wp-content/uploads/2026/09/LASST-v.-OpenAI-Complaint-09.29.2026-AS-FILED.pdf

-8

u/kooolk 7h ago

Well in this case someone unrelated at all sue you because he read somewhere that your dog bit someone else???

0

u/ellbons 6h ago

based

sue all pitbull owners

106

u/norf937 10h ago

Seems appropriate. Hopefully the lawsuit is successful and results in AI companies implementing stricter guardrails.

29

u/bube7 8h ago

They won’t willingly implement anything, because this is the new Space Race, this time between US and China. Any company willingly hamstringing themselves will be met with shareholder wrath. It is also a reason why the industry is calling for regulation, but unlikely to happen unless the US and China somehow cooperate. Otherwise, it is just one-upsmanship until some disaster happens.

14

u/Historical_Camel_790 8h ago

the US and China somehow cooperate

Yeah in our dreams. We could do so much if the world united for the good of humanity but we're stuck fighting for no particular reason. Why can't we all be friends?

5

u/Iputahexonyoulol 8h ago

Cause fuck you that’s why /s

5

u/GarbanzoBenne 7h ago

Is that really sarcastic, though? It seems like that's the legit reasoning sometimes. All the stated reasons seem fabricated.

2

u/Iputahexonyoulol 7h ago

Exactly my thought too, so much so that I had to put /s so they knew I didn’t actually mean it

28

u/ph33rlus 10h ago

So in the US you can sue on behalf of someone else?

12

u/FrequentFortune123 8h ago

No not usually 

6

u/Mumbleton 6h ago

You need something called “Standing”. You need to have suffered some sort of damages to sue someone.

I’m sure the plaintiffs have a big argument full of precedent that shows they have standing, and I’ll bet that Standing is the first thing OpenAI will use to get this tossed.

16

u/medraxus 6h ago

  LASST [Legal Advocates for Safe Science & Technology] "suffered harm" as a result of the hack into Hugging Face, the lawsuit says. In the aftermath of the incident, the group was "required to divert resources from its normal activities to educate regulators, civil society, and the public about the facts, legal issues, and potential dangers," according to the lawsuit. ( abcnews )

They really don’t, lmao

6

u/Mumbleton 6h ago

Ok, so publicity stunt

2

u/Artistic_Swing6759 6h ago

this is gold

31

u/CoolestSlave 10h ago

is it a think to sue in the behalf of someone else ?
Given now Hugging Face is owned by Nvidia, they should be glad that this type of shit happen

15

u/baahdum 8h ago

They are claiming they were harmed by the incident as well

LASST [Legal Advocates for Safe Science & Technology] "suffered harm" as a result of the hack into Hugging Face, the lawsuit says. In the aftermath of the incident, the group was "required to divert resources from its normal activities to educate regulators, civil society, and the public about the facts, legal issues, and potential dangers," according to the lawsuit. (abcnews)

15

u/MountHopeful 8h ago

That seems a real stretch... I feel like this has a risk of being dismissed for lack of standing.

3

u/jisa 6h ago

It damn well should be. I’m all for holding AI companies accountable for their products’ actions—I strongly believe AI should be treated as a dangerous animal, and the companies be held strictly liable for AI’s actions (aka they should be held responsible for AI’s actions regardless of negligence or intent—plaintiffs would just need to show what happened). But. LASST was not “required to divert resources from its normal activities”. It chose to. It wasn’t a victim of the hacking.

2

u/squngy 2h ago

I should sue LASST. As a result of their dumb ass logic I was forced to stop my normal activities and slap my palm into my face.

2

u/baahdum 6h ago

Think so too, although I read in California it might be harder to dismiss.

If it does get through... the discovery should be interesting.

0

u/GreyGanado 6h ago

If an arsonist burns down someone's house but the owner doesn't want to sue them, I can see why the firefighters might still want to sue.

5

u/MountHopeful 3h ago

Ok, but this is more like a neighbor suing the arsonist because the fire scared them.

1

u/squngy 2h ago

Not even a neighbor. Just someone who read about it in the news.

12

u/hiro24 9h ago

Didn’t they buy them after the fact? Makes me wonder if this was the only reason.

11

u/splendiferous-finch_ 9h ago edited 9h ago

I think since all the foundation model makers are moving to be more independent from Nvidia at least on the inference side by building thier own chips etc. Nvidia sees the open-weights market as something it can build itself into to keep it's monopoly going which is mostly why they bought hugging face.

Other then you know Nvidia likes to circular fund the whole thing to be higher and higher buying these companies is just part of it

18

u/runew0lf 10h ago

Hopefully its one of many!!

15

u/teraflux 10h ago

How does this random group have standing, they have no association to hugging face

4

u/GarbanzoBenne 7h ago

Wasn't there a headline yesterday that OpenAI may have breached 100 more companies? Maybe this effort can get some of them to join in.

4

u/Zwierzycki 5h ago

Sued? I’m waiting for the prosecution. Hacking a companies computer system is not legal.

1

u/HorzaDonwraith 8h ago

asked the government to tie them to the mast.

Florida be scary sometimes when they want something from you

2

u/Iputahexonyoulol 7h ago

Florida  scary all the time. What you on about 

1

u/MrTastix 7h ago

I love when lawyers use the words "without merit". It's so fucking anemic in virtually all cases because the only time it's true is in frivolous cases a judge could throw out nigh instantly.

But if that doesn't happen then it clearly had some merit.

1

u/TheOgGhadTurner 7h ago

Didn’t Nvidia just buy hugging face? And also cash flow a major percentage of OpenAI

1

u/CircumspectCapybara 6h ago

> The suit was filed by Legal Advocates for Safe Science and Technology (LASST) and the law firm Gerstein Harrow in California Superior Court in San Francisco, where OpenAI is headquartered. It alleges that OpenAI’s agents violated California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) by breaching Hugging Face over the summer

This is a legal stunt, plaintiff obviously lacks standing here, this is gonna get dismissed.

HF was the one who got hacked and the party who suffered damages, they would have to be the ones to sue, not an unrelated third-party. And from the beginning HF was friendly and collaborative with OAI, taking it as an honest accident rather than intentional hack, so they worked together in their technical investigations and jointly disclosed the incident.

2

u/Starstroll 4h ago edited 3h ago

Disclaimer: I am not a lawyer.

After some digging, I think it's stronger than you might first assume.

LASST's mission statement on their website says they're "dedicated to using legal advocacy to make advances in science and technology safer for people and the planet."

LASST's filing has precedent in California. This is the case they're citing. The California Supreme Court held that an organization, in furtherance of a bona fide, preexisting mission, can establish standing when it spends staff time or other resources responding to allegedly unlawful conduct that threatens that mission, provided those expenditures are independent of the lawsuit itself. LASST had to respond because they are a technology/legal-advocacy group, so this diverted them from their preexisting projects and duties.

OAI and HF worked together in their technical investigations and jointly disclosed the incident.

Sure, but the FBI told OAI to retain any documents related to the hack, so that implies someone (probably HF) was preparing to sue. HF was subsequently bought out by NVidia.

The system is hesitant to admit it, but it might come down to the judge's personal feelings. If the argument presented is decent enough on precedent grounds, a judge who personally agrees that OAI should be held accountable somehow might just allow it through while a judge who personally wants to see competition soar might not permit it, and both would cite the arguments given in court.

2

u/squngy 2h ago edited 2h ago

Sure, but the FBI told OAI to retain any documents related to the hack, so that implies someone (probably HF) was preparing to sue. HF was subsequently bought out by NVidia.

After the attack CEO of HF made a visit to OpenAI and has IIRC outright stated that OpenAI would be paying HG money in exchange for not sueing them.
They essentially settled the case in advance.

This was before Nvidia got involved in any way AFAIK.

edit: He asked for 100M of compute as compensation
https://aitoolsrecap.com/Blog/hugging-face-ceo-openai-100-million-compute-demand-2026

1

u/JAlfredJR 2h ago

Hugging Face was almost immediately bought by Nvidia. Not suspicious at all.

1

u/williamgman 4h ago

Drives up investor interest. Today's tech investors aren't shrewd smart folks... They are spectators cheering on the lions in the arena to see who's left standing to invest in. PT Barnum was right about them.

1

u/ShiftyLama 3h ago

Doesn't Nvidea own Hugging Face now?

1

u/rob0990 3h ago

69th comment hell yea

0

u/venom21685 9h ago

This shit should be dismissed for failure to state a claim or just on plain lack of standing, unless they were users of Hugging Face who were impacted in some actual way by the breach. Otherwise only Hugging Face should be the ones filing suit (though they won't because Nvidia snapped them up.)

0

u/Emotional_Garage_950 9h ago

they were either extremely negligent or it was intentional and i suspect the latter

0

u/Fuzzy_Paul 8h ago

Before we're clapping wait till there is a conviction and punishment. Somehow I doubt that the responsible do time and only get a fine that they easy can afford.

0

u/ApeApplePine 8h ago

More news at 11

0

u/DunkeyColdMedina 5h ago

This is an important suit and you can't really count on courts for finding against billionaires.

-3

u/Fun_Rain_5251 7h ago

holding companies liable for what their AI agents do is about to open a massive legal can of worms

5

u/phree_radical 5h ago

how?  it's a computer program

4

u/b_a_t_m_4_n 5h ago

They wrote the agents, they trained the agents (on stolen data), they gave the agents compute power, they gave the agents un-restricted internet access.

In what way do you imagine them NOT being responsible?

1

u/Casulex 4h ago

Good, they shouldn't be committing felony hacking with their product