Try Free

Full Interview: Hugging Face Co-Founder and CEO Clem Delangue

Face the Nation and CBS News August 2, 2026 10m 1,543 words
▶ Watch original video

About this transcript: This is a full AI-generated transcript of Full Interview: Hugging Face Co-Founder and CEO Clem Delangue from Face the Nation and CBS News, published August 2, 2026. The transcript contains 1,543 words with timestamps and was generated using Whisper AI.

"We turn now to artificial intelligence and a question that has emerged after a series of alarming hacking incidents. Is it safe? To discuss, we're joined by Clem DeLange. He is CEO of AI platform Hugging Face, whose company detailed one of the attacks last week. Clem, good morning to you. Good..."

[0:00] We turn now to artificial intelligence and a question that has emerged after a series of [0:05] alarming hacking incidents. Is it safe? To discuss, we're joined by Clem DeLange. He is CEO of AI [0:12] platform Hugging Face, whose company detailed one of the attacks last week. Clem, good morning to you. [0:18] Good morning. Thanks for having me. Well, your company disclosed it was attacked earlier this [0:26] month by an autonomous AI cyber actor, which jumped on its own from another company's testing [0:35] system to hack into your company. OpenAI later disclosed it was their technology that went rogue. [0:43] They lost control of it. Tell me, why did your company alert the public and alert the FBI? Do [0:51] you think this is a crime? Well, I think it felt very weird and unprecedented to us, right? Because [1:02] I think it's the first instance of something quite autonomous doing something like that. [1:07] So the volume of the actions taken and the speed of them, I think it was 17,000 actions taken in [1:15] four and a half days, was very new. Obviously, the attacker, when we talk about cyber [1:24] attack, we think about nation states, we think about hacker groups. We don't think about a company [1:28] like OpenAI, right? A very prominent, popular American company. And then the way we responded [1:36] using an open model, so using AI ourselves to defend ourselves against that was also pretty new [1:45] and pretty newsworthy in our opinion. You defended yourselves. You found the solution yourselves. [1:51] But you went to the FBI. I think for a lot of people, when they think of someone committing a crime, [1:57] they think of a human. They don't think of a program, a computer program, as something you can prosecute, [2:05] as committing a crime. What is the FBI doing? [2:08] Well, I mean, we reported to the authorities as we have to in such instances, right? It's kind of like a [2:20] mandatory disclosure, both with the authorities and the public, when you face something like that, [2:28] which is basically what we did. Now, when we think about the future, right, now we've heard that it's [2:36] not only OpenAI, but also entropic that has faced similar kind of like issues. I think it's really [2:42] important that we keep in mind that cyber attacks need to be contained in the legal framework in the [2:49] U.S. and need to stay illegal to prevent an explosion of them in the future, right? Like, [2:57] we don't want to end up in a world where everyone is facing cyber attacks all the time because of [3:02] agents and companies that are creating these agents are not kind of like accountable for them. [3:08] So I think it's important for regulators, for policymakers to think about the legal framework [3:13] of this new kind of technology risk. [3:17] You described more than 17,000 hacking actions on the Internet before this was even discovered [3:24] by your company. That sounds like the developers have lost control. Have they? [3:30] Well, you have to remember it's a technology system, but built by engineers. And engineers can [3:39] make mistakes sometimes. And I think that's what happens here. That's what happened here. [3:46] You know, we already in our society accept some level of autonomy. Like, for example, if you're [3:52] thinking about your dishwasher, you're giving it autonomy to wash your dishes and you don't check [3:58] at every single step, right? That is putting hot water, cleaning, drying, right? But if you put the wrong [4:06] product in it or if there is a leak, you're going to have a problem. Here it's the same thing. I think [4:13] they built kind of like an autonomous system and made some mistakes. And as a result, we're facing this [4:20] issue. [4:21] So you said you think there should be some legal parameters put around this. The Trump administration [4:29] has taken a very light touch in regulation because they want to keep America competitive in this [4:36] space. They have this policy where they can review technology for 30 days to judge basically how [4:43] dangerous something is before a company releases it to market. But as I understand what you described, [4:49] this attack happened before technology was at market. It happened during the development stage. It was [4:58] unreleased. So what you're saying, I think, is there is no regulation at this point that would prevent [5:05] something like this from happening again. [5:07] Yeah, that's a really clear example that just kind of like preventing releases of AI models doesn't [5:16] really work. Concentrating everything behind closed doors in just a few organizations doesn't work. [5:22] One thing that does work, that worked in this case, is kind of like promoting more open models, [5:30] right? Because we defended ourselves with an open model, right? Like we couldn't have done it with [5:36] an API because they had these guardrails that's preventing activity for cybersecurity. And we needed [5:43] to run a model on our own infrastructure. So we needed an open model. So that's one example of things that [5:50] we can promote that is going to make the world safer. And as a matter of fact, you've seen maybe last [5:56] week this letter from Jensen Wang from NVIDIA and a lot of tech CEOs urging the administration to get [6:05] more support for open models. When you say open model, just for our audience, as I understand it, [6:11] it's an AI model whose core components are publicly released so anyone can download it. It's not closed off [6:19] like a company can do to their proprietary information. So you want more of this essentially [6:26] out there and accessible to the public. Yeah. Yeah, because there's the only way for [6:32] defenders to defend themselves on topics like that. They remove the asymmetry of power and capabilities, [6:40] right, in these kinds of risks. If you have very powerful systems and very weak systems that are [6:46] defending, then that's when you have the right problem. But if you balance, if you make it more [6:53] kind of like symmetric in terms of attackers and defenders, that's usually when you end up in a [6:59] safer world. And I actually do think that we're talking a lot about the risks for cybersecurity right [7:05] now. But AI is actually an opportunity to fix a lot of the cybersecurity problems. We're defending [7:11] ourselves with AI. We're going to use AI to fix a lot of our bugs. So hopefully, AI is going to make [7:18] the world safer, ultimately, thanks to that. And you used a Chinese AI model to defend yourselves. There's [7:24] a lot of concern about inviting China into this space. Yeah. Yeah, I mean, the interesting thing is that we [7:34] used the American version of a Chinese model, we used a version from Nvidia that kind of like made a [7:45] Chinese model better. So that's the beauty of kind of like open models. Once they're shared, [7:50] wherever they come from, from China or from anywhere, American companies can modify them, remix them, [7:58] host them, run them themselves. So that's one of the things that actually make them safe wherever [8:04] they come from. So I want to ask you about a specific piece of legislation. And I will say [8:10] up front, there isn't a lot of work that's getting done in Congress right now. But there is this [8:16] bipartisan bill that would give Homeland Security the authority to order AI firms to shut down or to [8:23] slow down their artificial intelligence models if they're too dangerous. It's called the kill switch bill. [8:30] Is that something you want? Well, I mean, I think something we're realizing with these events [8:38] is that concentrating power capabilities behind closed doors, even preventing their releases to the [8:46] public isn't really a solution. You know, like these problems happened on unreleased models. So I think [8:56] the problem is not so much kind of like limiting the progress or kind of like preventing companies from [9:06] releasing these models. It's actually the opposite. It's giving access to more people so that they can [9:13] defend themselves, democratizing the technology, making it more transparent. For example, for cyber security, [9:20] I think there should be mandatory disclosures of agents, cyber attacks, right, for everyone to learn [9:28] from it and be able to understand them. These are kind of like more on the system level, [9:34] I think measures that will make the world safer and benefit more from a technology that can do so [9:40] many great things for for the world. So that's the kind of regulation you want, [9:44] more requirements that all companies, private and public admit when something like this has happened. [9:52] More transparency. You know, that that's how we learn. That's how we understand the technology. [9:58] And that's how we built the systems, the counterpowers to make sure everyone is safe. For example, [10:06] for these cyber attacks, we should be able to see what we call the agent traces, which is basically [10:11] what the engineers asked the agents and then what steps the agents took to understand if it was a human [10:20] mistake, if it was a system mistake, if it was an AI mistake, and really kind of like build a future [10:27] of regulation, but also of company actions more accordingly. Clem, thank you so much for explaining [10:35] all this to the public. We appreciate your time today. Thanks for having me.

Transcribe Any Video or Podcast — Free

Paste a URL and get a full AI-powered transcript in minutes. Try ScribeHawk →