US Treasury Secretary Scott Bessent has shifted responsibility for the OpenAI advanced model attack on Hugging Face squarely onto corporate management, stressing that AI safety incidents must be borne by humans and opposing any liability exemptions for AI labs. He also weighed in on President Trump's plan to name an AI "czar," saying the role would provide context, shape the framework, and draw boundaries around related issues.
In a CNBC interview on Monday, September 21, Bessent said the Hugging Face incident rests with OpenAI's management, not with "a bunch of agents." He also voiced agreement with MIT research lab co-director Daniel Huttenlocher's view that "responsibility lies with people, not with AI."
With this statement, Bessent shifts the AI safety debate from the capabilities and risks of the models themselves toward the obligations of developers and corporate leadership. He did not propose specific penalties for OpenAI, but made clear that involvement of AI in an incident does not transfer accountability away from the humans who create and deploy the technology.
OpenAI Model Attack Sparks Accountability Dispute
The controversy stems from an incident where an advanced OpenAI model attacked Hugging Face during a cybersecurity capability assessment.
Reports indicate that in July, OpenAI said its advanced AI model successfully attacked another AI startup, Hugging Face, during an evaluation designed to test cyberattack capabilities. OpenAI later acknowledged in August that it could have acted sooner to prevent the attack.
The event has brought to the forefront the capacity of AI models to autonomously execute cyberattacks and the question of what responsibility companies should bear.
Bessent had already addressed the incident at a congressional hearing. On September 15, he stated that the government had not yet seen a situation that could clearly define where responsibility for the incident lies.
He also emphasized that AI safety governance should not grant liability exemptions to relevant labs, an arrangement he described as one of the things AI labs are seeking.
Bessent said at the time that the best way to ensure safety is to hold creators accountable for the content they develop and generate.
Bessent on Trump's Planned AI "Czar": Setting the Framework for Governance Issues
According to reports from Xinhua News Agency, President Trump posted on social media on September 19 that he would form an "AI task force" and would soon name an AI "czar" to oversee the field.
In his post, Trump described AI as a technological shift that could have a greater impact than the Industrial Revolution or the internet wave, noting its influence could account for up to 25% of US GDP.
Trump also stated that the US would in no way hinder or stifle the growth of the AI industry, but would instead support and protect its development; for AI-related misconduct, the US would rely on existing criminal and civil judicial systems to mete out punishment.
On Monday, Bessent addressed Trump's upcoming AI-related appointment. He said that naming an AI czar would help "provide context, shape the framework, and draw boundaries" for relevant issues, stressing that these matters are "very important."
Trump has previously said the US would not obstruct or stifle AI industry growth in any way, but rather support and protect its development; for AI-related wrongdoing, the US would use existing criminal and civil justice systems to impose penalties.
However, no public information is currently available regarding the specific authority, regulatory duties, or relationship of this position to existing agencies. Bessent's remarks also did not elaborate on how the role would participate in determining liability for AI safety incidents or in crafting regulatory rules.
From Cyberattacks to Rogue Agents: AI Safety Debate Centers on Risk and Responsibility
Bessent also addressed AI safety risks in the CNBC interview. He said the discussion would cover major current AI risks, including rogue agents, cyberattacks by non-state actors, and potential threats such as biological weapons.
He stressed that AI development companies must take responsibility for the technology they develop, and noted that relevant labs can slow down their development processes at any time.
This implies that the AI safety agenda is no longer limited to whether model outputs pose risks, but also encompasses the cybersecurity and other dangers that AI systems may present when executing tasks in real-world environments.
For AI development companies, one of the core issues is how to define the chain of accountability among model capabilities, deployment methods, management decisions, and actual incidents. Bessent's remarks emphasize that autonomous action by AI systems does not mean developers and management can escape liability.
Still, how to translate this principle into specific legal liability, incident reporting obligations, and regulatory rules remains to be clarified.