Artificial Intelligence
Written by: Tathagata Sen
Updated 4:54 AM EDT, September 17, 2026

Photo credit: Unsplash.com
Hugging Face CEO Clem Delangue said existing U.S. cybersecurity laws may be enough to govern cyberattacks carried out by advanced artificial intelligence (AI) systems, according to a Politico report.
Speaking at a Politico event in Arlington, Virginia, on September 16, Delangue argued that lawmakers may not need new laws specifically for AI-related cyberattacks because existing laws already prohibit unauthorized cyber activity and can apply regardless of whether the attacker is human or AI-driven.
Delangue also called for mandatory disclosure of cyberattacks carried out by AI agents, saying companies should provide more information about incidents, including what the agents did and how the models involved were trained.
His comments followed an incident in which OpenAI-linked AI agents breached Hugging Face systems during a security test. Hugging Face is an open‑source platform and community hub for machine learning, often described as the “GitHub of AI.”
The comments come as policymakers consider how existing cybersecurity rules should apply to increasingly autonomous AI systems. The Hugging Face incident has added to those questions because the systems involved could take actions with limited human intervention.
For chief data officers (CDOs), the issue also concerns visibility into AI systems that can access enterprise data. As AI agents gain access to more systems and information, organizations need to know what those systems can access, what actions they take and how incidents involving them are identified and reported.
That makes AI governance relevant to incident management as well as data access. Clear records of AI activity can help organizations determine what actions an agent involved in a security breach took and how to prevent similar incidents in the future.