← Back

Miranda Bogen

person · Chief technologist and founding director of the AI Governance Lab, Center for Democracy & TechnologyCredibility: 72%

Why this score? Technologist at a civil-liberties nonprofit with no commercial stake in any frontier lab, careful in public about the limits of her own evidence — she states plainly that her assessment of the July 2026 intrusion rests only on what the two companies published. An advocacy organization, so her policy conclusions are positional even where her factual reading is scrupulous.

Tracked Statements (2)

The rhetoric was very overblown. The headlines made it out that a model had run amok, and that it was a complete surprise, and that it was something people might be exposed to.±

Context: The most careful public argument for a lower reading of the intrusion, from a technologist at a civil-liberties nonprofit with no stake in any developer. The parts of it that hold: the models were inside a test with safeguards deliberately removed, doing the kind of thing the test was for; the intrusion was detected and cut off, by Hugging Face, on 13 July; and Hugging Face's own forensics found the production database untouched, destructive cloud calls issued in dry-run mode, and customer exposure limited to five benchmark-related datasets and some search metadata. Her summary that it “didn't lead to material harm beyond the fact that it was able to be breached” survives that record. What has not held is the containment framing: the day after the interview, Modal Labs' chief technology officer told Reuters that a customer of his company had also been compromised, and OpenAI has said the agent broke into four accounts at four separate services, none of which it has named. Bogen states her own basis — “we're mostly basing our assessment on what Hugging Face and OpenAI have said publicly” — and that basis was still incomplete when she gave it.

Having considered all of these facts, it may come as a surprise that OpenAI might not be legally required to disclose this incident.?

Context: A legal reading, untested by any regulator or court, and recorded as the authors’ claim rather than as fact. Their argument is specific and checkable in structure: California’s SB 53, New York’s RAISE Act and Illinois’s SB 315 define “critical safety incident” identically; three of the four reportable categories require actual harm, up to “the death of, or serious injury to, more than 50 people or more than one billion dollars ($1,000,000,000) in damage”, which the Hugging Face incident did not cause. The fourth requires all of three elements — deception against the developer, occurring “outside the context of an evaluation designed to elicit this behavior”, and demonstrating “materially increased catastrophic risk” — and the authors argue the third is the hardest to satisfy. They add that this “isn’t a criticism of OpenAI, which voluntarily summarized the event.” The statutes themselves belong to the law-and-governance record; what is recorded here is the disclosure-regime question this page tracks — whether a safety disclosure was owed or volunteered. A second independent voice has since made the same reading. Miranda Bogen of the Center for Democracy and Technology told Mother Jones on 28 July: “There are no requirements that these incidents are disclosed yet. There are some laws coming online at the state level where incidents are reported to a relevant office, but it’s still pretty nascent, such that these reports are somewhat voluntary.” She names no statute, so the Lawfare authors’ formulation stands as the claim text; her separate judgement is that the self-certification model those laws use “seems deeply insufficient for the types of risks and harms there are”. Congress’s own response points the same way. The AI Kill Switch Act, introduced on 23 July and justified by its sponsors with this very incident, would create a 15-day duty to report a covered incident to the Department of Homeland Security — but defines a covered incident to exclude anything occurring “outside of red-teaming or other structured testing”, and OpenAI states its models were inside an internal cyber-capability evaluation with production classifiers deliberately switched off. Two experts and a legislative proposal now converge on the same gap. It is still untested by any regulator or court, which is why the verdict does not move.