Posted Jul 29, 2026 at 2:38 PM UTCEExternal LinkOpenAI hack of Hugging Face was “expected.”Former OpenAI board member Helen Toner has written for Fortune that OpenAI’s models exploiting Hugging Face is an “incident that has been expected for a long time.” We know this happened because of voluntary disclosure, Toner notes. “None of the current policies that aim to manage risks from frontier models would have mandated that the public — or even a government entity — be alerted.” She suggests changing our regulatory approach.Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.Elizabeth Lopatto
OpenAI hack of Hugging Face was “expected.”
Former OpenAI board member Helen Toner has written for Fortune that OpenAI’s models exploiting Hugging Face is an “incident that has been expected for a long time.” We know this happened because of voluntary disclosure, Toner notes. “None of the current policies that aim to manage risks from frontier models would have mandated that the public — or even a government entity — be alerted.” She suggests changing our regulatory approach. [Link: Helen Toner: the Hugging Face hack was just a matter of time and exposes a huge blind spot in AI policy | Fortune | https://fortune.com/2026/07/28/helen-toner-hugging-face-hack-openai-open-secret-blind-spot/ | Fortune]
OpenAI exploited Hugging Face models; incident disclosed voluntarily with no policy mandating transparency to regulators or public. Governance gap signals urgent need for binding frontier AI compliance mandates to enforce model security disclosure.













