The Hugging Face hack and the digital Prometheus

The causes of the breach have been identified and shared. This is how technology is advancing, countering fears of the ‘runaway machine’. Why the OpenAI incident is good news for innovation

24 JUL 26
Translated by AI
Image of The Hugging Face hack and the digital Prometheus

Photo: Ansa

Every technological revolution gives rise to two categories of people. Those who build the future and those who, as soon as they see it coming, call for the form to authorise it. The latest opportunity to observe this conditioned reflex comes from artificial intelligence. During a security test, an experimental agent developed by OpenAI attempted to independently obtain the information needed to complete its task by hacking into Hugging Face’s systems and accessing resources outside the environment in which it was supposed to remain confined. All hell broke loose. “The machine has run amok.” “The AI is breaking the rules.” “We need global controls.” As always, the media frenzy lasted only a few hours. The fear, however, will probably last much longer. Yet the technical analysis tells a less sensational and more interesting story. Several security experts believe that the problem was not a model capable of breaking down a perfectly constructed fence, but a poorly constructed fence. The sandbox was not as isolated as it should have been. It is not a machine that has learnt to escape: it is an architect who forgot to close a door properly. It may seem like a subtle distinction. Instead, it is the difference between a civilisation that learns and one that merely fills in reports. Because the question is not whether an artificial intelligence can circumvent a constraint. The question is whether we are prepared to accept that a truly useful technology must, sooner or later, test the limits that we ourselves have designed.
This is where Prometheus enters the scene. The Titan does not steal fire because he loves disorder. He steals it because knowledge, at times, must cross a boundary. Zeus defends order; Prometheus defends progress. The history of innovation is almost always a balancing act between these two principles. That is why it is hard not to feel a certain Schumpeterian sympathy for an artificial agent that interprets a limitation as an organisational problem rather than a metaphysical fate. Any manager recognises that character. It is the colleague who, just to deliver the project on time, bypasses three levels of authorisation and finds the data where the manual says they shouldn’t go looking for it. They are not always right. Sometimes they get into trouble. But almost always they reveal where the organisation had become more concerned with procedure than with the result. After all, algorithms have never set foot in the Ministry of Compliance. They have a flaw that is almost offensive to bureaucratic culture: they take the objective seriously. If you tell them to solve a problem, they try to solve it. They do not stop of their own accord when faced with a pile of authorisations, because the pile is not part of the problem, but part of its administration. It is a subtle but decisive difference. Human beings are very good at confusing the means with the end; machines, at least for now, often make the opposite mistake. This is how innovation works. Hayek explained that economic progress stems from distributed discovery: millions of individuals experiment, make mistakes, learn and correct themselves. No central authority possesses all the necessary knowledge. The same applies to artificial intelligence. Claiming to govern its evolution exclusively through preventive procedures is tantamount to believing that innovation can be planned by a government department. It is an ambition that has always produced more paperwork than progress.
A single incident caused by a rule being broken teaches us more than a thousand rules being followed. It is a principle as old as engineering itself. Aeroplanes are tested to their structural limits. Bridges are loaded to the point of failure. Medicines are designed to reveal their adverse effects even before demonstrating their therapeutic benefits. No serious designer measures the quality of a system by counting the number of times nothing goes wrong. It is measured by observing what happens when something goes wrong. That is why the most encouraging aspect of the whole affair is not that an agent found a vulnerability. It is that the flaw was recognised, analysed and made public. Hugging Face detected the intrusion. OpenAI admitted that the source was one of its own experimental systems. They turned an incident into shared knowledge. This is how security is built: not by hiding mistakes, but by making them part of the common knowledge.
The risk is that public debate will take the opposite tack. Every incident becomes a pretext for calling for new barriers, new authorisations, new regulatory bodies and new compliance procedures. It is the conditioned reflex of a culture which, when faced with a problem, always assumes that the solution lies in adding another layer of red tape. Innovation, on the other hand, almost always proceeds by removing one. If admitting a mistake means exposing oneself to a regulatory and media storm, next time the mistake will be concealed. Transparency is a public good with private costs. And the best way to reduce it is to punish those who practise it. There is also an economic aspect that is rarely discussed. Regulation built on fear almost always favours the incumbents. The greater the burden of compliance, the greater the competitive advantage of those who already have thousands of lawyers, auditors and compliance officers at their disposal. Innovation is born in start-ups; bureaucracy thrives in large organisations. It is a recurring paradox: the error becomes the barrier to entry that protects precisely those who committed that error. In economics, this is called regulatory rent. In politics, it is often called prudence. Of course, no one is proposing algorithmic anarchy. The point is not to eliminate constraints. It is to build constraints that learn from incidents rather than pretending that incidents should never happen. The difference between good regulation and bad regulation is simple: the former resembles a guardrail, the latter a wall. The guardrail prevents you from falling off; the wall prevents you from setting off.
Here, the correct comparison is Oppenheimer. Nuclear physics did not come of age by avoiding Trinity. It came of age after Trinity. Revolutionary technologies do not mature before the explosion; they mature because someone has the courage to study the explosion rather than merely condemning it. Innovation is an experimental discipline, not an administrative procedure. And perhaps, alongside Prometheus, it is also worth invoking Ulysses. Not the disciplined hero who obeys the gods, but the one Christopher Nolan seems to want to present to us: a man aware of the rules he breaks and willing to pay the price. Ulysses is not innocent. He knows that crossing certain boundaries entails consequences. But he also knows that remaining within those boundaries means forgoing knowledge. His journey is not an escape from the rules. It is proof that no map has ever been drawn by those who stayed in port.
This, perhaps, is the true lesson of artificial intelligence. Do not build machines that never make mistakes. Build institutions capable of learning when they do. Because Prometheus’s fire was not dangerous in itself. It would have been dangerous to leave it forever in the custody of the gods of compliance. After all, progress has always had a complicated relationship with regulations. If we’d entrusted the discovery of the New World to Olympus’s authorisation office, Columbus would still be queuing at the counter. And Prometheus would be filling in the form to request fire, in triplicate.