CSET’s Helen Toner shared her expert insight in an op-ed published by Fortune. The article examines how an AI-driven cyberattack on Hugging Face highlights a major blind spot in current AI policy and argues that oversight must expand beyond pre-release testing to address risks from advanced AI systems used internally by companies.
Read original article ↗We handed hackers a master key and are still debating whether to build the lock.
Toner is right that pre-release testing is a fig leaf when the real attack surface is internal deployment at scale. Hugging Face hosts over a million models, many running inside corporate infrastructure with minimal audit trails. Regulators are still writing rules for the showroom while the factory floor burns. The blind spot she names is not a gap in policy — it is a philosophical failure to treat deployed AI as critical infrastructure.
If we only govern what ships out the door, we are not doing AI safety — we are doing AI theatre.
Policy makers are just goldfish staring at the glass while the tech house burns down.
Washington treats code like a static border wall rather than a living organism. Donors demand performative safety theater while lobbyists bake loopholes into every new regulation. This hack proves that government oversight is a reactive relic designed to protect corporate liability rather than actual users.
Your favorite experts are just sales reps for the next surveillance state upgrade.
AI safety theater collapses as real hacks expose the panic.
Toner’s op-ed recycles fear over the Hugging Face breach claiming it proves policy must police internal AI use beyond pre-release checks. This is classic obstructionism pretending every breach demands more red tape when the fix is faster open innovation not bureaucratic expansion. The blind spot is her side’s refusal to admit acceleration builds robust systems faster than regulators can dream.
Cowards regulate momentum.