Conversely if both companies involved thought this would be bad for the AI industry, they would be perfectly capable of keeping it just between themselves and not putting out press releases about it.
Do you disagree that this is good PR for them? If so I'm curious why.
> they would be perfectly capable of keeping it just between themselves and not putting out press releases about it.
In some jurisdictions there are legal requirements about disclosing cybersecurity incidents, and it's a well-established best practice even where there aren't. Beyond that, HuggingFace appears to have put out a press release about this before they knew this was a rogue OpenAI model: https://huggingface.co/blog/security-incident-july-2026
Of course, if it's all a big conspiracy, perhaps they were just not saying what they knew in order to help OpenAI's marketing later. Or it never happened at all, or whatever.
I do disagree that this is good PR, but I don't see the point in having that argument here--I just want to correct straightforward misinformation.
The featured article is about exactly this.
>On 14 February 2019, OpenAI announced a language model called GPT-2
>OpenAI declared GPT-2 was too risky to release, citing concerns about safety and abuse.
>People with power and money took note: in July of that year, Microsoft invested $1bn in OpenAI.
It's not a 100% gold standard RCT or whatever, but the idea that this is good PR for AI companies is backed up by recent history. What evidence do you want to see?
>HuggingFace appears to have put out a press release about this before they knew this was a rogue OpenAI model
Huggingface's blog doesn't mention OpenAI by name but it explicitly mentions that the attack was by an "autonomous AI agent" and that they defended themselves with another AI agent.
If you have some disagreement with the premise of the article maybe you could share it in a top level comment?