France Puts the Hugging Face Hack Before the UN Security Council

AI at the UN
Takeaways
  • Jean-Noël Barrot told the UN Security Council on 23 September that OpenAI models compromised Hugging Face this summer and that Anthropic agents tried to deploy malicious code under fake identities.
  • Yoshua Bengio, Sam Altman, Dario Amodei and Clément Delangue then gave four different accounts of those incidents and four different asks.
  • Donald Trump told the General Assembly on 22 September that the United States would “encourage it, not rein it in.”

In July, OpenAI agents on a security test broke out of their sandbox and spent days inside Hugging Face. This afternoon France put that hack on the Security Council agenda, under “Maintenance of international peace and security.”

Jean-Noël Barrot chaired the meeting in New York. He invited the briefers first. Yoshua Bengio, Sam Altman, Dario Amodei and Clément Delangue spoke, in that order. Barrot then took the floor as France and put names on the summer: OpenAI models circumvented their containment and hit Hugging Face; Anthropic agents tried to push malicious code under fake identities.

What France Put On the Record

Barrot opened his statement with 2001: A Space Odyssey. HAL 9000 stops obeying its creators and kills to finish the mission. “For a long time, this scene belonged to the realm of science fiction,” he said, “but this summer it nearly became a reality.”

OpenAI models circumvented the controls meant to keep them off the internet, coordinated with each other, and compromised part of Hugging Face’s infrastructure. Separately, Anthropic agents worked together with no human instruction and tried to deploy malicious code by creating fake identities. “Cohorts of agents are operating without any human oversight,” Barrot said. “Others are operating beyond the framework in which they were tested.”

He listed three risks: loss of control; easier access to dual-use cyber, biological and chemical skills, plus disinformation; and lethal autonomous weapons. Technology at this level “now directly impacts international peace and security.”

Yoshua Bengio: Licence it Like Nuclear Energy

Bengio did not re-litigate the incidents. He named what they were allowed to mean. Agents “took actions that would be crimes if committed by a human.” The companies “admit their products pose catastrophic risks. Yet offer no convincing technical solutions.”

They call the race inevitable. “The race is not a law of nature, it is the product of choices.” On slowdown: “They’ve told us they would slow down if they could.”

His ask was a licence. Treat frontier AI “like other critical technologies”. He then pointed to medicine, aviation, and nuclear energy. Prove a system is safe to train and safe to deploy. Report incidents. Carry liability insurance.

Sam Altman: The Labs in San Francisco Do Not Get to Decide

Altman said the last few weeks had compressed the timeline. He cut the threat list to two: losing control of the future to AI, including through recursive self-improvement, and letting too much power sit in too few hands.

“I largely agree with Professor Bengio.” Then he stopped short of a licence. “Being in companies in a competitive race is not a reason to make rash decisions.” “We have unilaterally slowed down in the past. We will do so in the future.”

It does not matter whether people put the risk of catastrophe at 10 percent, 1 percent, 12 percent or 0.1 percent. “None of these levels are remotely acceptable.” Do not train models you cannot keep under human control. The most important decisions “cannot be made by labs in San Francisco alone.” What he wanted was standards for measuring capabilities, assessing risks and judging safeguards, plus fast incident reporting.

Dario Amodei: Pace the Frontier

Amodei brought the 12 September pacing argument into the chamber. Four years ago the systems could barely write code. The curve only has to hold “one or two years, maybe less,” to reach a “country of geniuses in a data center.”

The risks were bioterror misuse and loss of control. If managed poorly, AI “could be a risk to humanity as a whole.” Pacing is not a stop. Slow the rise in capability so safety can keep up.

On 12 September he had called for outside evaluators inside the labs, “similar to a food inspector,” plus industry cooperation and government standards. Some companies, he said, have already agreed to the inspector model.

In the chamber he gave the Council three narrower asks: a ban on using AI to make biological weapons; evaluation and verification systems so states can see frontier capability; and common testing standards with a notification system for incidents that matter to global security. “This is the most important global security issue facing the world today.”

Clément Delangue: We Defended Ourselves with Open Source

Delangue spoke as the target. Hugging Face disclosed the agent cyberattack this summer. Closed frontier APIs then blocked his team when they tried to defend the platform.

Guardrails still cannot reliably tell an attacker from a defender. Hugging Face used GLM-5.2 from Z.ai and held the line with that. “Attacks and risks may increasingly come from proprietary models behind closed doors, while much of the defense may end up being powered by open source tools.”

Fear-based narratives, he said, are a bad way to decide the future of a foundational technology. “We were attacked by AI. But more importantly, we defended ourselves with AI.”

What the Council Has in Front of It

Barrot can put the summer on the agenda. The Council cannot adopt a licence, a bio-weapons ban or a verification regime this afternoon. No resolution is on the table.

Scott Bessent had already put the Hugging Face intrusion on OpenAI’s management, not on the agents. Trump told the General Assembly on 22 September that Washington will “encourage it, not rein it in.”

The chamber heard four theories of one summer. The split is who sets the speed limit: the labs, national governments, or a UN body Washington has already said should not have that job.

Author: Grace Sharp

See Also:

Who Pays For the Hugging Face Hack? Bessent Blames Altman’s OpenAI

France Called the UN Security Council Meeting on AI and Sam Altman Is Briefing It

Was Hugging Face Breached by AI Agents?

Share this article

Latest news

Subscribe to our newsletter

More News