[Standard caveats for the Hugging Face hacking thread.]
[The mainstream coverage of the story has been sensationalistic and alarmist, with many details badly reported or out-and-out wrong. That doesn't mean you shouldn't be scared. LLM-based agents are getting disturbingly good at breaking through cybersecurity, and in this one area, they will only get better.]
[The potential for extensive and sometimes catastrophic harm is immense. You don't have to believe in Rogue AI and the coming robot apocalypse. If anything, some of the skeptics, like Cal Newport and Gary Marcus, are among the most concerned.]
[Imagine a world where every bad actor, from cyberterrorist all the way down to two-bit scam artist, had access to the world's greatest team of hackers. Or a world where any moron playing around with a computer could accidentally shut down the power grid. You don't need stories of Rogue AI to make that scenario scary.]
I've seen a lot of True Believers online railing against the argument that the uproar over the Hugging Face incident is all hype being generated by the frontier model companies for their own nefarious reasons. Curiously, though I follow the skeptic community (Marcus, Newport, Carl Brown), I've never actually come across anyone making these charges. The consensus in that group seems to be that these safety concerns are both real and disturbing. Gary Marcus has gone so far as to describe them as potentially catastrophic.
That said, it's important to make the distinction between "all a massive conspiracy" and suggesting that some of the executives at these companies might be trying to spin recent events in their favor. There are literally trillions of dollars at stake here in an industry that was widely considered a bubble of unprecedented size.
Which brings us to...
OpenAI delays IPO as Sam Altman cites growing safety concerns
Aidin VaziriOpenAI will not go public this year, CEO Sam Altman said in an interview released Saturday, delaying one of the most anticipated stock market debuts in Silicon Valley as the artificial intelligence industry faces growing scrutiny over safety.
Altman told Fortune that taking the San Francisco company public now would be the wrong move while OpenAI and other major developers work through questions about how quickly to build more powerful systems.
This story has been getting a lot of play. Based on the headlines and ledes, choosing to forgo a trillion-dollar IPO out of safety concerns would certainly indicate that Sam Altman and OpenAI were taking these concerns very seriously.
If it were true.
If you've been closely following the story, or just reading below the fold in most of these articles, you would find that there has been extensive, well-sourced reporting from credible sources showing that the decision to delay the IPO until 2027 was made a couple of months ago for reasons that had nothing to do with safety.
Here's Forbes from late June:
OpenAI hired bankers and lawyers eyeing an initial public offering as early as the third or fourth quarter of this year, with CEO Sam Altman pushing them to engineer a $1 trillion valuation, the Times reported, citing three people involved in the talks.
Over the past week, OpenAI’s advisers have cautioned the company that a public listing may not be met with enough enthusiasm due to the volatile public tech market, per the report.
When advisers offered a choice between waiting until 2027 for a $1 trillion debut or accepting a lower valuation for a faster one, Altman called any cut to the trillion-dollar figure a "nonstarter," one person in contact with him told the Times.
At the risk of putting too fine a point on it, being able to rebrand the delay from from being a sign of a struggling company to being a bold statement of principle is a big win for Altman and his company. The original story had been a huge black eye and had come at a time when a growing number of analysts and commentators were speculating that OpenAI was struggling to survive, particularly when compared with Anthropic.
Once again, this is not meant to suggest that they did it on purpose. The PR angle alone is not enough to make up for the legal and regulatory concerns that the Hugging Face incident has likely put into motion.
There is, however, at least one plausible scenario where OpenAI's cybersecurity fuck-up could actually be the best thing to happen to the company in years. Anthropic being forced to delay its IPO due to safety concerns and the inspiring example of its competitor would be a major lifeline for OpenAI. (Though so far it doesn't seem to be working.)
Hugging Face was a major body blow to an industry that was already about as popular as a venereal disease. It's silly to assume the leaders of these companies wanted it to happen, but it's naive to assume they'll be completely honest and altruistic about their response either.



