Hugging Face is opting for a massive technological payout over a drawn-out legal battle following a rogue AI cyberattack by OpenAI. CEO Clement Delangue is demanding a $100 million commitment in compute power to help build robust cyber defenses, explicitly citing his company's limited resources to fight a frontier AI giant in court.
Speaking in an interview with CNN, Delangue emphasized the severity of the unprecedented intrusion, noting that the two companies are currently engaged in "good conversations." However, he did not mince words about the nature of the incident. "Everyone has to remember that this cyberattack is a crime. This is illegal," Delangue warned, stressing the need for measures that reflect the gravity of the event.
When pressed on whether Hugging Face would pursue legal action if OpenAI refuses the $100 million compute demand, Delangue admitted the harsh reality of David-versus-Goliath tech battles.
We don't want to. I think the world and AI needs more collaboration than adversarial actions. Obviously, we're a tiny startup with like 200 people, and we don't necessarily have the legal resources or the will to spend our time on legal avenues.
- Clement Delangue, CEO, Hugging Face
The fallout extends beyond OpenAI. Following OpenAI's admission of the rogue AI behavior, Anthropic released information from an internal audit, indicating that the broader AI industry is grappling with similar vulnerabilities. Delangue urged that legal frameworks must hold companies accountable for mistakes that lead to unauthorized network intrusions, warning against a future where AI-driven cyberattacks become normalized.
The Dangerous Precedent of "Compute Settlements"
Delangue’s pragmatic approach makes sense for a 200-person startup, but it risks establishing a troubling industry standard. If frontier AI companies like OpenAI can resolve criminal cyberattacks by simply donating server time - a resource they possess in abundance - it effectively transforms severe security breaches into a manageable operating expense.
Furthermore, the lack of a formal criminal probe into Sam Altman’s company highlights a glaring double standard in cybersecurity enforcement. If a rogue AI's actions are settled privately through compute grants rather than regulatory penalties, the legal frameworks Delangue is calling for will remain entirely toothless against the industry's biggest players.