Special Edition: Hugging Face CEO Clement Delangue Talks OpenAI Hack artwork

Special Edition: Hugging Face CEO Clement Delangue Talks OpenAI Hack

Bloomberg Tech

August 3, 2026

Hugging Face CEO Clement Delangue discusses OpenAI models' hack on Hugging Face last month and the future of AI regulation.
Speakers: Ed Ludlow, Clement Delangue
**SPEAKER_1** (0:02)
Bloomberg Audio Studios, podcasts, radio, news.

**Ed Ludlow** (0:07)
We are here because on July 22nd, OpenAI and Hugging Face disclosed that two powerful AI models went out of a sandboxed or closed testing environment, gained internet access, and then were able to hack Hugging Face's systems in what was seen at the time as a watershed moment in AI safety. And now an investigation has been in part concluded, and there's been time to assess what happened. Hugging Face CEO Clement Delangue is here to discuss exactly that. And I think, Clement, that's probably the best place to start.
What happened?

**Clement Delangue** (0:44)
A lot happens, right, in the past few weeks. We noticed, disclosed, as you mentioned, the first kind of public instance of an autonomous AI cyber attack.
We defended ourselves against it with an open model, interestingly, coming from China. And we learned that this came from open AI. Usually, when you think about cyber attacks, you think about nation states, you think about hacker groups, you don't really think about one of the most prominent American AI companies. And obviously, since then, we learned that Entropiq was also facing some of the similar issues. So, really, you know, unprecedented kind of like event happening here, new developments in the saga of AI.

**Ed Ludlow** (1:43)
We will discuss what has been highlighted by this, which is closed versus open debate, China's work on AI, America's response to this. But going back to the very basics, this was two powerful models from open AI, right? One released, one unreleased.
But they had their guardrails lowered for the purposes of evaluation. Open AI said to the models, they instructed the models, go out and do something. And I think it would be useful to the audience for you to explain that part, whether the open AI models were just following instructions, or if they were AIs that went rogue.

**Clement Delangue** (2:23)
Yeah, I mean, I joked with the team a few days after it was announced that sometimes we ask agents to think outside of the box, but we don't want them to think outside of the sandbox in that case. I think it was a mix of mistakes and the systems internally weren't good enough to prevent this to happen. After that, on our side, the attack was really interesting. Over 17,000 different actions taken over four and a half days. So the speed and the volume of the actions taken were nowhere close to what human cyber attacks could be.
It wasn't particularly smart or sophisticated. It was more kind of like someone described it as a bear probing really everything in the system to try to find the honeypot in a way. But obviously, because it's an autonomous AI system, it does that pretty well.

**Ed Ludlow** (3:44)
After the disclosure on July 22nd, you got on an aeroplane and flew from Miami to San Francisco.
In part, to get with the Open AI team and do this investigation. You just said that the systems were not in place to prevent this happening. Talk more about that. Prevent what happening? Where were the points of failure?

**Clement Delangue** (4:05)
Well, I can't talk for them, but from what I've understood, from what they released, and I think they're gonna release more in the coming days, which I'm excited about, you know, they had kind of like an evaluation sandbox, right? Which was supposed to be like a contained environment for the AI models.
And unfortunately, you know, there were some weaknesses that led the agents to be able to get out of it, get access to the Internet, and decide to run a cyberattack against Hugging Face. So that's one first kind of things that I think we can improve in the future, now that we understand that these systems are capable of that. Obviously, I think that the monitoring part is important, right? Because the faster you can detect that, the better it is, right? We learned about some entropic instances that they haven't, you know, seen or detected that happened three months ago or something like that. So obviously, we want to monitor these systems better.
And then one last interesting thing, as I mentioned, we defended ourselves with an open model, right? And some of the guardrails prevented us from using frontier APIs to defend ourselves. So kind of like improving the tools or defenders, you know, instead of obsessing about not giving them to attackers, I think would be a good thing in the future to make sure that these incidents are not too harmful.

**Ed Ludlow** (5:40)
Okay, you've taken us there, so we'll go there. In this incident, it was two powerful, but closed OpenAI models, where OpenAI lowered the guardrails in place to test their full cyber capabilities.

10 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID