Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?
Hugging Face put up a blogpost saying that they reported the hacking to the authorities: https://huggingface.co/blog/security-incident-july-2026
It's not clear whether they mean authorities for their US HQ or the French authorities.
But I can't find any announcement of the follow-up. Is there a case open against OpenAI the company? Is their management interviewed by the authorities? Anyone detained yet?
I guess the people who left the model running unattended risk at least a suspended sentence here in France.
Where are concerned citizens making inquiries on this matter and reporting in their viral blogposts?
26 comments
[ 2.5 ms ] story [ 52.8 ms ] threadMy assumption is no (but I am no expert in US law with regards to this). It would in any case become a very expensive law suite.
I heard about it on the radio (local Johannesburg radio station) before I saw it on HN. The economist had a full article up about it before the end of the day, and in the evening Sky news had talking heads up chatting about what it all meant while clearly being clueless.
Someone spent a LOT of money to turn this into a PR exercise for both companies. We'll never hear the entire story about what happened but I'm sure there was a lot of handshaking going on behind the scenes.
OpenAI could be considered a legal actor under the CFAA, notably: unauth'd acc. §1030(a)(2), fraud §1030(a)(4), (kind of a stretch but) damage §1030(a)(5), and conspiracy.
I miss ya, Aaron.
It’s a particularly poor example of government cruelty.
depending then on openai response and hugging faces reported severity/damages etc it could go further to a settlement or court.
since in France i think u cannot sue like in the US, it might not be appealing to pursue further legal action due to involved costs/time.
Also its unlikely an engineer would get penalty unless it can be proven they did it with malicious intent. If its an operational mistake afaik if there is no huge damage or human cost (injury or worse) then it would be a business / executives thing not a workerbee problem
No, that doesn't mean I'm in favor of this scaremongering over open weight models and Chinese sources. US companies aren't to be trusted to develop AI responsibly anymore than any other source and they shouldn't be the only ones allowed to wield its power. This is just anticompetitive behavior by a company who sees new competition entering their market, threatening their market share.
what happened could be negligence if it caused unintentional damage, or what amounts to tortious interference, however that probably requires knowledge of possible damages.
Honest question, I was unable to find what you are referring to, what is that grounded in and can I just put a open weight LLM in between any malicious code I’d like to attack others with and be in the legal clear in the States?
LLMs don’t do anything without an initial prompt, OpenAI should be better than anyone else at monitoring what their models do and the responsibility for e.g. driver assistance still lies with the human outside specific exemptions for which law had to be drafted and which come up additional obligations.
Also, what other people have said about it being turned into a (mutually beneficial?) marketing opportunity.
Far less than 1% of all crime which happens is prosecuted, why should OpenAI be prosecuted?
Since the necessary context isn’t provided, this just seems like an utterly stupid question. The obvious answer is “OpenAI probably isn’t being prosecuted because crimes are almost never prosecuted”.
It’s like asking why I don’t get arrested every time I get stopped shitfaced drunk at the La Turbie police checkpoint. The answer is obvious: The cops are looking for brown people, there are no taxis here and after 2am everyone driving in the vicinity of Monaco will be drunk. i.e. nobody gives a shit
Sometimes better to work with people when things go wrong via good intentions rather than turn around and sue them and break relationships completely.