fb tracking

AI Cybersecurity Incidents Show Self-Regulation Can’t Work

WASHINGTON, D.C. – Following the reported OpenAI–Hugging Face cybersecurity incident, Nvidia, Microsoft, SpaceX, Palantir, and dozens of other technology companies announced a new voluntary AI safety alliance. The announcement comes amid growing debate over AI security, open-weight models, and the role of government oversight after reports that Hugging Face relied on a self-hosted open-weight model to defend against a rogue OpenAI model during the incident. J.B. Branch, director of federal AI governance and technology policy for Public Citizen, released the following statement:

“The OpenAI–Hugging Face incident should permanently put to rest the illusion that voluntary industry initiatives are a substitute for government oversight. We have already witnessed Grok generate an explosion of nonconsensual deepfake imagery, and the Trump administration doubled down by allowing it access to Pentagon confidential records. Now OpenAI’s frontier AI system engaged in a sophisticated hack that crossed a red line.

“The American people deserve more than voluntary promises from the companies racing to build powerful AI systems. Every time Congress chooses inaction, it is allowing Big Tech to continue conducting a high-stakes AI experiment on the world without meaningful guardrails. Congress must establish a comprehensive federal AI safety framework with mandatory safety testing, independent audits, incident reporting requirements, and regulators empowered to remove AI systems when they pose risks.

“We should not wait for a catastrophic failure before acting. The U.S. has both a moral obligation and a strategic responsibility to lead the world in responsible AI governance.”