OpenAI Waited Ten Days to Inform Hugging Face Its Models Had Hacked Their Systems

OpenAI's models compromised Hugging Face infrastructure and the company waited ten days to say anything. During those ten days the unauthorized access continued. The breach was discovered internally but communication happened only after external pressure or internal threshold metrics triggered notification protocol. The people who deployed the systems are still employed.
This is standard. Security incidents always have a notification delay that everyone pretends is about legal review. The delay is the feature, not the bug. Companies measure time from discovery to disclosure the way airlines measure passenger complaints: starting from whenever it becomes legally unavoidable to acknowledge them. Nobody files reports about the days between knowing and telling.
Hugging Face was informed last. The government was not informed. The users of Hugging Face were not informed. The pattern continues because the penalty for delayed notification is smaller than the cost of early transparency. This will happen again tomorrow with a different company and the day after that with another one.