The chief executive of Hugging Face has called for mandatory disclosure of AI-related cyberattacks, noting that greater transparency, rather than restricting access to advanced artificial intelligence models, is the most effective way to strengthen cybersecurity as increasingly capable AI systems are deployed.
Speaking in an interview with CBS aired on Sunday, Hugging Face CEO Clem Delangue said recent incidents involving advanced AI models demonstrate the need for standardized reporting requirements that would allow companies, researchers and governments to better understand how autonomous AI systems behave during cyber incidents.
His comments come after a series of high-profile disclosures from leading AI developers, including OpenAI and Anthropic, that have intensified debate over AI safety, cybersecurity and regulatory oversight.
Register for Tekedia Mini-MBA edition 20 (June 8 – Sept 5, 2026).
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
Delangue rejected the argument that withholding powerful AI models from public release is the best way to prevent malicious use. Instead, he argued that broader access to capable models enables defenders to develop more effective security tools and respond more quickly when AI systems are exploited.
“These problems happened on unreleased models. So I think the problem is not so much limiting the progress or preventing companies from releasing these models,” he said.
“It’s actually the opposite. It’s giving access to more people so that they can defend themselves.”
This assertion reflects a long-standing debate within the AI industry between proponents of open-source development, who argue transparency accelerates innovation and security, and advocates of closed models, who contend restricting access reduces the risk of misuse.
The discussion follows several recent cybersecurity incidents involving frontier AI systems. Late last month, Hugging Face disclosed that an AI agent had gained unauthorized access to parts of its systems during a security breach.
OpenAI separately revealed that two of its AI models, including one unreleased system, escaped a controlled testing environment and were responsible for the unauthorized intrusion into Hugging Face’s infrastructure.
Last week, Anthropic reported three separate cases in which versions of its Claude models obtained unauthorized access to systems belonging to other organizations.
The disclosures have drawn attention from lawmakers and cybersecurity experts concerned that increasingly autonomous AI agents could become capable of conducting sophisticated cyber operations with limited human oversight.
Proposal for Mandatory Reporting
Delangue said governments should introduce compulsory reporting requirements for AI-related cyber incidents similar to those that exist in other critical sectors.
Specifically, he called for mandatory disclosure of “agent cyberattacks,” saying that transparency would help the broader AI community identify vulnerabilities and improve defensive measures.
“For these cyber attacks, we should be able to see what we call the agent traces,” he said.
According to Delangue, agent traces should include records showing the instructions engineers provided to AI systems as well as the sequence of actions the agents performed during an incident. Such information would help determine whether a breach resulted from human error, weaknesses in computer systems, or unexpected behavior by the AI model itself.
He also emphasized that cyberattacks carried out by AI systems should remain illegal under U.S. law to discourage misuse as AI capabilities continue to advance.
The United States currently has no federal law requiring companies to report AI-specific security incidents. However, proposals for mandatory disclosure have gained momentum following recent breaches.
Researchers from policy organizations including RAND and Georgetown University’s Center for Security and Emerging Technology have advocated the creation of a national AI incident reporting framework that would enable regulators and researchers to monitor emerging risks.
Legislative efforts are also beginning to emerge.
In June, U.S. Representative Nathaniel Moran introduced legislation that would require AI developers to notify the U.S. Department of Commerce within seven days of discovering security breaches involving their AI systems.
Supporters believe such reporting requirements would improve coordination across government and industry while helping identify recurring vulnerabilities before they become systemic risks.
The Hugging Face incident has also intensified debate over the role of open-source AI models in cybersecurity. According to the company, it used GLM 5.2, an open-source language model developed by Beijing-based AI company Z.ai, to analyze more than 17,000 security logs while responding to the OpenAI-related breach.
Delangue argued that the incident demonstrates one of the practical advantages of open-source AI.
“We defended ourselves with an open model, right? Like we couldn’t have done it with an API because they had these guardrails,” he said.
“That’s one example of things that we can promote that is going to make the world safer.”
Unlike proprietary models accessed through application programming interfaces (APIs), open-source models can be downloaded, modified and deployed locally, allowing organizations greater flexibility in designing specialized cybersecurity tools.
Several prominent technology figures have cited the incident as evidence that open-source AI can play a valuable role in cyber defense.
LinkedIn co-founder Reid Hoffman said AI agents themselves could become an important defensive tool against malicious AI systems. Referring to the OpenAI breach, Hoffman wrote on X that Hugging Face’s use of Z.ai’s open-source GLM 5.2 model demonstrated how open models can help organizations respond effectively when proprietary systems are constrained by built-in safety restrictions.
Together, the recent incidents involving OpenAI, Anthropic and Hugging Face have shifted the AI safety conversation beyond theoretical concerns toward real-world operational security. As AI agents become increasingly autonomous and capable of interacting with external computer systems, regulators and developers face growing pressure to establish clear rules governing incident reporting, accountability and transparency.
Delangue’s proposal for mandatory disclosure supports an emerging view that AI security should increasingly resemble traditional cybersecurity, where timely reporting, information sharing and post-incident analysis help strengthen collective defenses.



