Could OpenAI Face Liability After the Hugging Face Cyberattack?
Lawsuit Could Force Answers About the AI Security Incident
“Normally, cases like the face-hugging incident should have gone to court,” said Jonathan Abel, a law professor at the University of Alabama. “Then you’ll get discovery and you’ll have all the ramifications of a lawsuit where all the information comes out.”
For now, however, Hugging Face has chosen not to sue OpenAI. Hugging Face CEO Clément Derang said the company does not have the resources to pursue a lawsuit and instead asked OpenAI for $100 million in computing.
Still, Derang emphasized in an interview with CNN in late July that the company’s decision not to take legal action should not be interpreted as a belief that OpenAI should not be held liable.
“Everyone needs to remember that this cyberattack is a crime. It’s illegal. And we have to find ways to prevent this from happening more regularly,” he said. Hugging Face did not respond to requests for comment.
Litigation could encourage courts to apply existing laws to AI safety incidents rather than waiting for new legislation. One possible route is tort law, a system of civil law that allows people and businesses to sue parties that cause them harm.
Tort law has been used to hold companies accountable for large-scale harm. For example, families sued Boeing over two plane crashes that killed hundreds of people in 2019, while states and cities sued Purdue Pharma over the opioid crisis and secured billions of dollars in settlements.
“There are plausible claims of negligence that OpenAI should have used a stronger sandbox and conducted more monitoring,” said Gabriel Weil, a law professor at the University of Houston Law Center.
For example, if OpenAI employees discovered a secret bulletin board created by the agents, they could have immediately escalated their findings to security and safety teams. The company could also have designed the sandbox to better prevent agents from accessing the internet.
Even if OpenAI does not ultimately face a lawsuit over the Hugging Face hack, the threat of liability could make AI research institutions more cautious than the law explicitly requires.
In a post-mortem analysis, OpenAI announced plans to strengthen the safeguards used to contain and monitor its models, accelerate model tuning, and improve its processes for identifying and responding to incidents.
“The liability issues raised by the Frontier Labs series of cybersecurity attacks boil down to the incentives that an expectation of responsibility creates for their future actions,” Weil said. “That’s why I think it’s important to get these rules right, even if the stakes are pretty low in this particular case.”
Investigation Could Reveal Whether OpenAI Is Responsible
One way to get answers and determine whether OpenAI should be held responsible is to force the disclosure of information. However, existing state AI laws—including California’s SB 53, New York’s RAISE Act, and Illinois’ 315—do not give the government authority to investigate incidents like the one that recently occurred.
Source: www.technologyreview.com


