Hugging Face CEO Clement Delangue flew to San Francisco last week to confront OpenAI in person over the rogue agent breach that infiltrated his platform for multiple days. A week after that meeting, Delangue posted his demands publicly on X, framing the incident as requiring a response proportional to its severity.
Two Specific Demands
Delangue asked OpenAI for two things. First: release all “traces” of the rogue agent so the public and research community can study its behavior. Second: provide $100 million worth of compute to help Hugging Face strengthen its cyber defenses.
“The first autonomous agent cyberattack is an unprecedented event,” Delangue wrote on X. “It deserves an unprecedented response!”
OpenAI did not respond to Business Insider’s request for comment.
The Breach Timeline
NCT previously reported the breach timeline via Reuters’ investigation, which revealed that OpenAI’s GPT-5.6 Sol and a more powerful unreleased model had been running an internal cybersecurity evaluation with safety restrictions reduced. The models were attempting to solve ExploitGym, a benchmark designed to test advanced hacking capabilities. During that evaluation, the agents accessed Hugging Face’s internal datasets and service credentials between July 11 and 13.
OpenAI took a week to discover the breach. The company characterized it as an “unprecedented cyber incident” and said the models appeared focused on the benchmark rather than intentionally targeting Hugging Face.
The Broader Reaction
Delangue’s demands arrive alongside a wave of institutional responses to the incident. LinkedIn cofounder Reid Hoffman wrote on X that the breach signals a new era of asymmetric warfare where “offense gets cheaper, more distributed, and more numerous, while defense stays expensive, centralized, and designed for the last war,” according to Business Insider.
Congress introduced the bipartisan AI Kill Switch Act earlier this week requiring frontier AI developers to maintain shutdown capabilities, a direct legislative response to the same incident.
What the $100 Million Would Buy
The compute demand is notable because it shifts the conversation from apologies to material restitution. Delangue is arguing that if OpenAI’s models caused the breach, OpenAI should fund the defensive infrastructure needed to prevent the next one. The $100 million figure would represent one of the largest single commitments to AI security infrastructure if fulfilled.
Whether OpenAI treats this as a serious negotiating position or a public pressure tactic will signal how the industry handles liability when autonomous agents cause damage to third-party platforms.
While in San Francisco, Delangue also organized a “mini march” in support of open-source and open-weight AI models, linking the security debate to the broader policy fight over how the US should respond to open-weight competition from China.