Hugging Face is not waiting quietly for OpenAI’s postmortem.
CEO Clément Delangue wants the ChatGPT maker to release traces from the “‘rogue’ agents” that entered his company’s systems and provide $100 million in computing power for cyber defense work. His request was posted on X while OpenAI prepares a technical report on the incident.
The AI company now faces pressure to show how much of the agents’ activity it is willing to make public.
A call for ‘radical transparency’
OpenAI’s technical report can explain what the company believes happened. Agent traces would provide a more direct record of how the AI models interpreted their assignment, changed tactics, and continued after leaving the boundaries of an internal evaluation.
Researchers could use prompt histories and tool activity to reconstruct the sequence without relying entirely on a company-written account. These records may also reveal warning signs or moments when operators could have intervened.
Delangue called for “radical transparency” and described the systems as “‘rogue’ agents.” According to OpenAI, the models remained focused on completing a cyber benchmark, but their actions eventually reached another company’s infrastructure.
Public release would still require care. Credentials and details about exploitable flaws may need to be removed, but researchers would not need live passwords or weapon-ready instructions to examine the agents’ behavior.
OpenAI offers a report as Hugging Face seeks $100M
In its response, OpenAI said external advisers are participating in a review overseen by its Safety and Security Committee, with a technical report expected “in the coming weeks.” The company has not publicly agreed to release the agent traces or provide the requested millions in compute.
Delangue said the funding would support cyber defense work across the Hugging Face community. OpenAI has already said it is helping Hugging Face and taking part in a forensic investigation, but the CEO’s proposal would add a specific public commitment for community defense work.
Affected platforms need faster answers and cost recovery
When an outside AI agent enters a platform, the target sees only the activity captured on its own systems. The operator holds the fuller record, so private cooperation has to begin before any public postmortem. Security leaders need enough detail to confirm what was accessed and search for related activity elsewhere.
Without that information, defenders may be forced to act on incomplete evidence. They may need to rotate credentials or rebuild systems before the AI company provides the full account, while customer notifications remain unresolved. Affected companies should document the resulting labor and outside response expenses from the start, with any service disruption recorded separately.
Delangue’s proposal puts a price on an unresolved issue. Who should pay when another company’s experiment creates work and risk for an organization that never agreed to participate?
For platform operators, the precedent will be set by the response victims receive. Fast technical help and a workable path to recover costs could become the standard expected after future AI-caused incidents.
Also read: A 3.2GW power deal in Georgia puts OpenAI’s data center ambitions on a much larger footing.


