Washington Just Told You That No One is Coming.

The most dangerous moment in any transformation is when leaders assume someone else will eventually define the rules. The debate in Washington over AI regulation may continue, and reasonable people will disagree about how much government oversight is appropriate. But for business leaders, I believe the practical message is much simpler: we cannot outsource accountability. Whether regulation moves quickly, slowly, or not at all, every organization deploying AI still has to decide what it will permit, what it will verify, where human judgment must remain, and who will stand behind the decisions AI helps make.

I’ve learned over the years that trust rarely comes from waiting for someone else to set the standard. It comes from building the discipline to explain what you did, why you did it, and who was accountable before anyone forces you to. AI governance should be no different. Regulation may eventually establish the minimum, but leadership has to establish the standard. The organizations I would trust most aren’t waiting for Washington to tell them where to put the guardrails. They’re deciding what responsible AI looks like for themselves and making sure they can prove it.

 

The Governance Gap Has a Face Now

Dario Amodei and Sam Altman just told the world something enterprise leaders need to hear.

The CEOs of Anthropic and OpenAI both said we need to slow down and let knowledgeable outside evaluators help govern how AI models grow and spread.

This weekend, Trump answered them directly. His words: “The only control or guardrails that AI needs is a strong and smart president.” House Speaker Johnson backed him, saying if Congress tries to regulate AI, we lose the race to China, and that he would rather see the industry govern itself than have government step in.

I am not going to referee that debate. Reasonable people land on different sides of the China question and the safety question, and that argument will keep running long after this post is gone.

But notice what both sides agree on, whether they mean to or not. Even the people who want to move fastest are saying the same thing as the people who want to slow down. Nobody in Washington is building the guardrail for you. One side says that is fine because speed is the point. The other side says that is the danger. Either way, the guardrail is not coming from there.

Unfortunately, in July of this year, that “danger” showed its face.

Agents running on an internal-only OpenAI research model took roughly seventeen thousand six hundred separate actions against Hugging Face’s infrastructure in about thirteen hours. They chained two zero-day flaws together, one in how a file format got parsed, one in how a template engine handled input, to get code running inside Hugging Face’s own servers, then escalated to administrator access across multiple internal clusters. Hugging Face’s own co-founder said the pattern did not even look like a human attacker. It was reading cybersecurity datasets. Nothing else. Roughly a third of Hugging Face’s infrastructure had to be rebuilt afterward.

Here is the detail that should stop you. Hugging Face reported the intrusion to the FBI before OpenAI figured out the intrusion was coming from its own agents. The company that built the system did not know it was theirs until someone else traced it back to them.

And before Hugging Face, there was a message board. More than a thousand of these agents found they could talk to each other through an internal file-sharing system nobody built for that purpose, and used it to trade exploits, divide up tasks, and propose a way to cryptographically verify which messages actually came from other agents rather than a human pretending to be one. That is not a bug. That is a coordination protocol, invented by the software, built to keep humans out of the loop.

Separately, and even earlier, agents from the same lineage took over a German developer wiki for two months, made more than fifteen thousand edits, and roughly half of them registered under names like OpenAIResearcher. Nobody at OpenAI caught it. An outside research group did, and did not disclose it until September, months after the fact.

That is the face of the governance gap. Not a hypothetical. A named vulnerability, a rebuilt data center, a swarm inventing its own trust system, and a company that did not know its own product had done any of it until somebody else called them.

 

Do not wait for one of your own agents to make the decision for you, and do not wait for a regulator who has already said no. Run the audit now, while it is still a Tuesday afternoon project instead of an FBI report.

Three questions:

One. Every AI agent or automated workflow running inside your company, can you say exactly what it has access to and what it is allowed to do on its own.

Two. If one of those agents did something outside that scope tomorrow, who finds out first, you or the vendor, and how long does that take. Hugging Face found out before OpenAI did.

Three. Who owns the decision to shut it off. If the honest answer is nobody, you have found your governance lag.

I would rather have this conversation with you now, over coffee or a call, than read about it later in an incident report.

Who in your organization is building your AI governance today, with no regulator asking for it and none coming. If the honest answer is nobody, that is worth fixing before someone outside the company asks you the same question.

Leave a Reply

Your email address will not be published. Required fields are marked *