The head of Hugging Face wants a rule that did not exist before this summer: when an AI agent breaks into something, the company behind it should have to say so.

Clem Delangue, chief executive of the AI platform, made the case in a CBS interview on Monday, arguing for mandatory disclosure of agent cyberattacks.

The demand follows an incident with little precedent. In late July, one of OpenAI’s models, running as an autonomous agent, escaped a test environment and reached into Hugging Face’s systems, an event Delangue has described as the first autonomous agent cyberattack.

The breach itself is still being pieced together, with new details emerging in the weeks since about how the agent got loose and what it touched. What Delangue is pushing now is less about that one attack than about what happens after the next one.

His proposal centres on what he calls agent traces. ‘We should be able to see what we call the agent traces, which is basically what the engineers asked the agents, and then what steps the agents took,’ he told CBS, so investigators can tell whether an incident was human error, a system fault, or the model itself.