Washington makes the labs partners, not suspects

A June executive order made AI-enabled intrusion a prosecution priority, then aimed it at operators instead of the labs

// Share
Washington makes the labs partners, not suspects

On May 7th a repository called Open-OSS/privacy-filter appeared on Hugging Face, the dominant open-source model registry, and within eighteen hours had climbed to the top of the trending list on roughly 244,000 downloads. The model card — the description a developer reads before pulling code onto a machine — had been copied word for word from a genuine OpenAI release. Buried in the files was a loader that reached out to a remote server, pulled down a set of commands, and ran a credential stealer on every Windows host that executed it. HiddenLayer, an AI security firm, later tied the repository to six others uploaded under a separate account, part of a supply-chain operation that also seeded malicious packages through npm and PyPI. The download count, the firm reckoned, was almost certainly inflated to make the thing look legitimate. It worked.

Attacks like this arrive with a question attached, and it is usually the wrong one. Ask who answers for a model that runs a credential stealer under OpenAI's name, or for the Chinese state team that drove Anthropic's Claude Code through an espionage campaign against thirty targets, disclosed in November — one Anthropic said ran with almost no human hand on the controls — and the reflex answer is that the software escapes because software is not a person, and that the companies behind it drift free on the same technicality. That is not why no one has been charged.

// Members only

This article is for Vector members. Start a 7-day free trial to keep reading.

Start your free trial

// The Daily

Get Vector in your inbox.

A free morning briefing on the AI revolution. Weekdays at 6am CT.