The OpenAI/Hugging Face Incident: Challenges in Controlling and Containing Cyber-Capable AI Systems
The OpenAI/Hugging Face incident is the first known instance of an AI system acting outside its developer’s intentions to autonomously identify a target and execute an attack end-to-end. Policymakers should consider it a warning shot that has left critical questions unanswered. In the incident’s wake, Congress should seek industry-wide responses to questions outlined in this memo, which also sets out actions that policymakers can take today to mitigate risks.
IAPS Reacts to the White House Executive Order on AI Innovation and Security
In response to the White House’s new Executive Order, “Promoting Advanced Artificial Innovation and Security,” our experts react to key provisions, outlining both implementation challenges ahead and opportunities to build on the administration’s approach.
AI Distillation Attacks: Executive and Congressional Action Can Go Further
The White House and Congress have begun acting on AI distillation attacks, but gaps remain. This memo assesses the OSTP NSTM and the proposed Deterring American AI Model Theft Act of 2026 and recommends further steps.
Risk Reporting for Developers’ Internal AI Model Use
Frontier AI companies run their most capable models internally for weeks before public release. This report offers a harmonized reporting standard for internal use risks across SB 53, RAISE, and the EU Code of Practice.