cmiles8
5 hours ago
This seems like as a good an opportunity as any to break out the Computer Fraud and Abuse Act.
They want “regulation” but we already have it. Hacking is illegal. Start locking up those responsible for this mess and I assure you they’ll “have a handle on it” quite quickly.
i2talics
4 hours ago
IMO: The inability to prosecute OpenAI for these things is proof that the AI industry is already "too big to fail". Why didn't HuggingFace try to seek legal liability against OpenAI when it had explicit confirmation that they had been hacked? Because HF understands that it needs OAI and the rest of the AI industry to continue to exist and be in good legal standing, for the interest of HF's own self preservation. This is what it means for something to be too big to fail.
pj_mukh
4 hours ago
>>Why didn't HuggingFace try to seek legal liability against OpenAI when it had explicit confirmation that they had been hacked? Because HF understands that it needs OAI and the rest of the AI industry to continue to exist and be in good legal standing
But also, what was the material damage to HuggingFace? AFAICS, it rapidly increased their profile to the point that Jensen claims he paid too much for HF, because he bought right after the hack.
alwa
3 hours ago
Perhaps some of that premium was because Nvidia definitely knows it needs OAI and the rest...
estearum
2 hours ago
Does CFAA require material harm? I don't think so.
rcxdude
37 minutes ago
No, but if it's criminal it's also not up to the victim whether a prosecution is started.
sillyfluke
3 hours ago
>But also, what was the material damage to HuggingFace?
Just contemplating the idea that you're going to be the target of thousands of relentless brute-forcing AI agents till the end of time and that you're too dependent on Big AI to do anything about it would be enough for many people to throw in the towel.
Jensen seems to be whining in order to deflect criticism of the purchase price. I'm more inclined to believe HF warmed to selling after the incident because of the damn-if-you-do-damned-if-you-don't legal quagmire. Nvidia is one of the only entities that would be positioned to able to sue OAI in the future, or compel them to take more preventative measures.
cmiles8
4 hours ago
Less “too big to fail” and more the ecosystem is too circular. OpenAI could blow up and it wouldn’t take out the economy in the way the banks would have in 2008. It would create a world of hurt for VCs and their LPs but that’s a fairly isolated ecosystem in terms of the whole economy. Theres a lot of thinking saying better they impose now and wipe out on the private market than letting them go public and this is a public market problem.
leonidasrup
3 hours ago
They are already “too big to fail”.
" Our analysis suggests that the recent investments in AI-related categories have contributed significantly to the real GDP growth in 2025. It has surpassed the contribution of IT components to the real GDP growth made during the dot-com boom, both in levels and as a share of GDP. As firms continue integrating AI into their operations and building the infrastructure required to support it, these categories are likely to remain significant drivers of investment well into 2026 and beyond. "
https://www.stlouisfed.org/on-the-economy/2026/jan/tracking-...
citrin_ru
2 hours ago
They do contribute to GDP growth but society at large sees no benefits from this growth. Governments like growth because it allows to collect more taxes and reduce the budget deficit. But AI companies are not paying taxes because they are not yet profitable and even profitable tech companies are bad tax payers (they actively exploit tax loopholes, the most famous is the Double Irish but it's no longer the current scheme AFAIK).
jcranmer
3 hours ago
I don't think it's so much "too big to fail" as it is the fact that all of the AI companies have been similarly reckless in their drive for frontier AI. So if you establish the precedent that an AI company can be held legally liable for its recklessness, well, all of them can be held liable, and those costs start to add up fast.
__MatrixMan__
3 hours ago
HuggingFace's opinions shouldn't be a blocker.
If I run over your mailbox maybe we can come to an agreement where you don't sue me, but if I was driving recklessly I've still committed a crime that you cant absolve me from.
It should be the same re: losing control of your agents.
TedDoesntTalk
4 hours ago
HuggingFace can’t file criminal charges, including under the Criminal Fraud & Abuse Act. Only district attorneys can do that- or the federal equivalent.
sscaryterry
4 hours ago
Luckily, other jurisdictions are going to really give it to them, in the coming months.
The orange man's influence doesn't extend as far as he thinks.
cobbzilla
4 hours ago
It’s a basic tort, HF could file a civil suit and probably win. But they don’t, for the same reason DoJ doesn’t press charges: TBTF
4ndrewl
4 hours ago
Being bought by nvidia also probably helped...
lenerdenator
3 hours ago
I don't know if OpenAI's necessarily too big to fail. It could simply evolve and make a few changes - switch back to its original goal, fire everyone at the company who has spent more than an afternoon on Stanford's campus - and probably succeed with burning a lot less cash.
Remember, the original idea for OpenAI was to make open (thus the name) AI models that could only generate a maximum return of 100x for the investors. There was none of this hyperscaling, proprietary technologies, pure profit motive, etc. until later on.
I think it ultimately comes down to ideology. Simple financial math has nothing to do with it and never has. SV and DC, at least today, have a lot of beliefs in common. It can really be summed up as "divine right of CEOs". These are the "best and brightest" who came from the right parts of the country, who went to the right schools (even if they didn't finish their degrees), and ran in the right circles. They don't simply receive the opportunity to make unfathomable wealth and power; they're owed it. If they do something, by default, it must be right, and if a circumstance comes in their way, it's the circumstance that is wrong.
That's why you don't see a small motorcade of black Chevy Suburbans headed to these companies' headquarters from the local DHS field office. They aren't wrong; the expectation that the AI agent doesn't hack into government websites is wrong.
cj
3 hours ago
This is going to make for a great documentary in 5 years.
john_strinlai
5 hours ago
cfaa heavily relies on intent for prosecution (hence why researchers arent typically locked up). it would be difficult to argue that openai intended to hack other companies.
there's probably better/more likely to succeed avenues to pursue rather than the cfaa
jordanb
4 hours ago
They could make that argument the first time it happened but the next time or the fifth time I don't see how they can still credibaly claim to not know that the computer they control was going to do that
john_strinlai
4 hours ago
>I don't see how they can still credibaly claim to not know that the computer they control was going to do that
that's not intent, though. that would be negligence.
CodeWriter23
4 hours ago
Not a lawyer but I think training a model with hacking skills they explicitly prevent the public from accessing without doing anything to stop the model itself from using those demonstrates intent.
john_strinlai
4 hours ago
what you described is negligence. unless you can prove that openai specifically targeted huggingface and specifically instructed their model to hack huggingface, it would not be intent.
anyone pursuing this will have a much easier time pursuing negligence causing damage or something along those lines rather than confining themselves to the cfaa's requirements.
it is unclear to me why people want to use the cfaa so badly. not only would it be harder to hold openai responsible, but a shitty cfaa ruling could also bring along some undesired side effects for security researchers, which i would prefer to avoid.
CodeWriter23
2 hours ago
Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder. There is a line between intent and negligence that puts acts over the line to intent if intentional acts led to a harmful incident.
I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products. Squeeze one disgruntled employee or another.
john_strinlai
2 hours ago
>Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder.
i am unaware of any case where someone was convicted of first degree murder from a drunk driving accident. my searches came up empty as well. are you able to pull one up?
>I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products.
to successfully prosecute a cfaa case, you would have to prove that openai employees intended to hack specifically into huggingface. not that they wanted a PR boost.
i dont get why everyone's got a hard on for prosecuting this as a cfaa case. skip the cfaa case, go for gross or willful negligence + damages. it'll be significantly easier to hold openai accountable that way.
daveguy
an hour ago
Clearly we need to update the CFAA to include criminal prosecution for negligence.
jordanb
4 hours ago
How many times does it have to happen before they no longer get to claim that they didn't intend for it to happen?
If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts "oopse!"
john_strinlai
4 hours ago
>If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts "oopse!"
yes, they look very silly. but that's not how intent works.
openai is being negligent (willfully so, in my opinion). but i have seen no evidence that they intended to specifically hack huggingface. which is the part that the cfaa wants.
again, there are other laws and other ways to hold openai responsible. but the cfaa is a poor choice.
jordanb
3 hours ago
Again how many times before intent is clear? This is HN thinking law is software.
At some point it becomes clear that openai should expect this to happen and so when they keep doing it, it is because they intend it to happen.
When the mobster says "it'd be a shame if something happened to this place" the law recognizes that as a threat due to the mob's history of making such statements before burning places out.
john_strinlai
3 hours ago
>Again how many times before intent is clear?
i have been an expert witness on several cfaa cases. the number of times a company is negligent is not a factor when it comes to determining the intent of each charge.
>This is HN thinking law is software.
this is me relying on my experience with these types of cases.
devin
4 hours ago
Willful negligence or gross negligence, then.
rot09
3 hours ago
This lines up. In the infosec community it is well known that OpenAI did not hire many security engineers or researchers pre-April 2026.
There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was very delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers.
john_strinlai
4 hours ago
indeed, that'd be a better angle than a cfaa violation
EGreg
4 hours ago
So then… you’re liable?
https://www.brandonjbroderick.com/new-york/dog-leash-laws-ne...
cmiles8
4 hours ago
Criminal negligence is a thing too
EGreg
4 hours ago
https://jtnylaw.com/2025/08/new-yorks-leash-law-realities/
Plaintiffs seeking damages must show that owners knew or should have known about the dog’s patterns. Past complaints or vet records help build a strong case.
john_strinlai
4 hours ago
i am not exactly sure what this comment has to do with mine, sorry.
jsrozner
4 hours ago
Just like boeing's execs didn't intend for their planes to fall out of the sky? I guess they didn't get in trouble either.
john_strinlai
4 hours ago
>Just like boeing's execs didn't intend for their planes to fall out of the sky?
correct, i dont think any boeing exec wanted their planes to crash and then made specific choices with a clear goal of causing them to.
instead, they made negligent choices that led to unintended outcomes.
jsrozner
2 hours ago
Agreed. But in today's world in which outcomes are well-separated from behaviors (e.g. the exec cuts testing budget and the plane crashes), I think it's time that we start treating negligence as willful.
This would have positive impacts on employees of META, Boeing, Purdue pharma and related, and the AI companies. By positive, I meant that the people whose choices are negatively affect society would actually be punished meaningfully so that they are dissuaded from taking such action. Personal liability needs to be increased as well, and to the best our ability we should ban the sale of director and officer liability insurance.
ofjcihen
3 hours ago
Mens rea is often established through circumstantial evidence.
Repeatedly doing something that results in a specific outcome, even if that outcome is not explicitly specified or requested as the preferred outcome, can still be evidence of intent.
semiquaver
4 hours ago
> Hacking is illegal
I am not a lawyer, but I seriously doubt the feds could win a CFAA conviction on the Hugging Face fact pattern, even if they wanted to charge it.
CFAA has specific intent requirements, and unlike some laws, negligence does not suffice. The agents can not have legally cognizable intent and it’s unlikely there’s anyone at OpenAI who intended for the hacking to happen (if there was, the case is easy).
Existing laws don’t contemplate AI agents that have independent goals. We need new ones, the existing laws are not remotely sufficient.
sscaryterry
3 hours ago
The existing laws are more than adequate.
semiquaver
3 hours ago
I gave an example of why they are not.
Could you explain what your legal strategy would be to overcome the intent requirement of the CFAA? If openAI didn’t intend to hack anything and agents can’t intend to do anything at all, and the CFAA doesn’t permit negligence to stand in for intent, seems to me like the existing law does not cover the situation everyone keeps saying it does.
sscaryterry
3 hours ago
Requiring intent is very specific to your jurisdiction, many, if not most other jurisdictions do not require intent.
In the UK, any form of unauthorised access may be prosecuted.
semiquaver
2 hours ago
No, the UK’s equivalent law specifically requires human intent and mens rea:
https://www.legislation.gov.uk/ukpga/1990/18/section/3 (1b.)
https://www.legislation.gov.uk/ukpga/1990/18/section/1 (1c.)
I’m told that the UK is a relatively authoritarian country where citizens have no real rights, so perhaps it can be charged anyway, but the plain language of the statute would seem to bar it.
sscaryterry
an hour ago
> Unauthorised acts with intent to impair, or with recklessness as to impairing,
Can you see the ", or with recklessness as to impairing".
Edit: You seem troubled. The UK is not like you describe at all. We do not have ICE running around. Instead, we have the opposite problem.
lenerdenator
3 hours ago
> independent goals
AI does not have goals. These are statistical models of language patterns that people shape into different tools, and that people direct to do things. If I fire up an OpenAI prompt, and enter no input, it is not going to do anything.
No, someone at OpenAI is running the model with some sort of prompt and allowing it to just follow the numbers to do whatever it wants, up to and including breach of government computer systems.
Whether that means anything to the CFAA prosecution, I don't know. I'm not a lawyer, but the use of language treating these agents like they're something other than tools at the direction of humans is bad.
It's more like me firing off a rifle into the air on the Fourth of July with no regard for where the bullet lands. I knew that it must come down somewhere, but fired anyways.
I don't really see the harm in charging someone under the CFAA. Let's see if a jury agrees with the charge or not. If not, write new laws.
semiquaver
2 hours ago
> AI does not have goals
You can try to language-police all you want, that doesn’t change the fact that the best way to describe the reality of the effects that LLMs have on the real world is to use language that analogizes to human concepts.
lenerdenator
2 hours ago
That, in turn, allows for people to just point at the agent as a human analog and shirk responsibility. Understand: that's the goal of a lot of people who don't have anyone's best intentions but their own in mind.
Ultimately, they do nothing without humans in the loop. The prime mover here is a person who can bear at least some legal consequence for what the program does, even if it's just having to deal with an investigation.
eurekin
4 hours ago
I still can't fathom my company application security decision. Found pretty damning requests in our logs. Escalated. Expected it would result in at least reporting the TOS break from the originating place (one of cloud providers). Instead of that, they just went: "yeah, but we don't have logs". Provided them. "Yeah, but that ip doesn't resolve". I matched real ones from the load balancer. "There could just be many of them". There was one. When I had all the evidence gathered, they looked at me and finally told:
- It's just an Independent Security Researcher.
- So that's it? You will do no action?
- Correct
nickff
3 hours ago
There is almost no will to prosecute big-business shenanigans until the scheme or organization collapses. See back-dated options during dot-com, SBF-FTX, Libor scandal, etc.
egillie
5 hours ago
can we legally treat ai companies like parents of children? if a child drives a car into a storefront, the parent is responsible for the damage, and at some point you might even criminally charge the parent if there was gross negligence
cmiles8
5 hours ago
The law already works like that. You can’t write some computer code and automation, set it loose, and then go “oops the computer did it.” It’s not a defense. While it may be hard to nail down which specific engineers to lock up, the corporation as a whole absolutely can be charged criminally.
As Mitt Romney once said “corporations are people.”
andrewla
4 hours ago
Hate to say it but I don't think you're right on the legalities even in the children's case. In the US anyway, in most jurisdictions [1], if the child's act was not malicious, then parental responsibility is not automatic, but is contingent on the result being foreseeable [2] by the parents.
[1] Hawaii and Louisiana are strange in this regard. Some other states have a version of this but severely cap the amounts.
[2] "foreseeable" here standing in for a broad set of legal standards that roughly map to negligence/gross negligence/recklessness on the part of the parent
egillie
4 hours ago
"I don't think you're right on the legalities even in the children's case" almost certainly true :) I guess I'm wondering why we aren't seeing legal action for these events yet? are these not foreseeable?
meowface
5 hours ago
That would require mens rea. This may be criminal negligence, but it wouldn't be more than that. (I am basically 100% sure none of the employees or execs are intending or desiring any of these outcomes, regardless of the very large number of people who believe in conspiracy theories about regulatory capture and other sinister motives.)
I'm totally on board with treating it as gross negligence requiring hundreds of millions or billions of dollars paid in fines and compensation to victims, but don't act like this is more than what it is.
voxic11
4 hours ago
The CFAA's main hacking charge has a high bar for intent. But the CFAA also has a separate "damaging a protected computer" charge (basically to criminalize DOS attacks) and that charge only requires negligence not specific intent.
cyanydeez
5 hours ago
But wouldnt that be bad for the shareholders? Why wont anyone think of the economic impact to the vulner billiinaire minority?