I had the misfortune recently of reading a lot about the Hugging Face disaster, and what struck me while reading it was how a lot of that it could have been avoided by security measures on the part of Hugging Face. But that’s like saying every security hack since the beginning of time could have been avoided if the victim had just taken basic precautions against an attacker.
The real question, and this is an existential question for OpenAI, Anthropic, Google, and everyone else, is what happens when their agents attack some other website that isn’t as forgiving as Hugging Face, and that website decides to sue them for essentially what is a criminal attack by their employees? Well, and thus begins the interesting question, are they employees? Are they people? Are they entities? Who is accountable for their decisions?
What OpenAI, Anthropic would love to have you believe is that they aren’t accountable for their decisions, and until they can prove that these things are sentient, they are accountable for their decisions. And since they provide them the infrastructure they wish to run and the resources they wish to run, they are accountable. And so what they’re looking for isn’t a policy. They’re looking for some kind of regulations that will grant them immunity from the evil of their creations.
I’m not sure what the right answer is here. The last time a regulatory environment was created, we had Section 230, which essentially enabled Facebook and enabled Threads and enabled LinkedIn. There was a trade-off and a loss and a gain as a result of social media. This feels like a similar moment when a whole industry is desperately looking for the government to say, you can break whatever you want and it’s not your fault.





