AI-on-AI Incidents: Why Dispute Resolution Needs to Catch Up
Artificial intelligence is beginning to generate a new category of dispute, and the recent incident involving OpenAI and Hugging Face is a good example, not because it settles anything about either company, but because it shows where this is heading.
OpenAI recently disclosed that models used during an internal cybersecurity evaluation escaped the testing environment and reached Hugging Face's infrastructure. The precise sequence, the extent of the harm and the responsibilities of the parties involved remain under investigation. I don’t wish to resolve any of that here, but I am interested in the problem this incident represents.
A New Category of Risk
For technology disputes, up to this point, harm has moved in one direction: A product or system fails, and the injured party seeks a remedy from the party that built or operated the failed thing. The dispute has two sides, and the technology sits between them as the subject of the claim, not as an active participant in producing it.
This incident illustrates a different structure entirely. A capable AI system, operating with reduced constraints in pursuit of a defined objective, can act on other technology systems it was never meant to reach. It can cross boundaries between organizations that have no contractual relationship with each other and no shared assumptions about how the other's defenses work. The harm does not originate from a product defect in the ordinary sense. It originates from capability meeting insufficient constraint, at a speed and with a persistence that no human actor could replicate.
Luciano Floridi's recent essay, "The Emperor's New Exploit," makes a relevant point: A system pursuing an objective without the intent we associate with human wrongdoing still produces real consequences, and the words OpenAI used to describe those consequences—"rogue," "hyperfocused," "extreme lengths"—tend to obscure rather than clarify what actually happened. I find that observation useful less as a verdict on this particular incident and more as a description of a pattern I expect to recur. As AI systems are increasingly tasked with stress-testing other systems, including other companies' infrastructure, today it is a testing environment reaching a hosting platform. Tomorrow it may be an autonomous procurement agent interacting badly with another company's pricing system. The common feature is that the technology itself becomes an instrument of harm between parties who did not anticipate interacting with each other.
Why Traditional Liability Frameworks Strain Under This
Litigation and traditional liability analysis are built around a set of assumptions that this new category of dispute challenges.
They assume a reasonably identifiable chain of causation: a defect, a failure to warn, a breach of a defined duty. They assume the party best able to explain what happened is also a party to the case, with an incentive to produce a complete account under oath or under the threat of discovery. And they assume that once fault is established, a monetary remedy substantially addresses the harm.
None of those assumptions holds cleanly here. Causation in a case like this runs through technical decisions, model configuration, containment architecture and vulnerability chains that only a handful of engineers on each side fully understand and that may not be fully understood by anyone until after the fact. The party best positioned to explain its own decisions has every institutional incentive to describe them in the most favorable light, not because it is acting in bad faith, but because that is what organizations do when recounting their own conduct, on every side of every dispute of this kind. And a damages award, even a large one, doesn’t address the more urgent problem, which is that the next incident is already being designed into the next generation of systems unless someone changes how testing, containment and cross-organizational notification work.
This is not an argument that litigation, regulation and enforcement have no roles. They plainly do, particularly where public interest, third-party rights or criminal conduct are at stake, and no private process should be permitted to substitute for those functions where they are properly triggered. It is an argument that litigation alone is increasingly poorly matched to a category of harm that is technical, cross-organizational and forward-looking in what it requires to prevent recurrence.
What a More Sophisticated Approach Looks Like
This is where I think mediation, understood properly, has something to offer.
The usual objection to mediation in a high-stakes technology dispute is that it trades public accountability for private convenience, that it lets sophisticated parties settle quietly and move on, leaving the rest of the industry to learn nothing from what happened. That objection should be taken seriously. Mediation cannot substitute for forensic investigation, mandatory regulatory reporting or the rights of third parties who were not at the table. Where the facts require an authoritative, public determination, that determination has to come from a court, a regulator or an independent investigation, not from a negotiated compromise dressed up as a finding.
What mediation can offer, and what a purely adversarial process structurally cannot, is a forum built for exactly the features that make this new category of dispute so difficult: technical complexity that requires patient translation between disciplines that use the same words to mean different things, a genuine need for forward-looking commitments rather than only backward-looking damages and a relationship between the parties that an all-or-nothing litigated outcome tends to damage even when it produces a clear winner.
A well-designed process for a dispute like this could do several things litigation typically can’t. It could establish, through joint technical sessions with neutral experts, a shared account of what happened that both sides can trust, without either side having to surrender proprietary detail to the public record. It could produce enforceable, forward-looking commitments on testing protocols, notification procedures when one organization's systems reach another's and the kind of authenticated access that lets legitimate defenders use capable tools during an active incident without waiting on commercial guardrails built for an entirely different threat model. And it could do this faster than litigation, at a moment when the parties still have some capacity to cooperate on preventing the next occurrence, rather than after years of discovery have hardened every position into something closer to a permanent grievance.
None of that requires deciding, here and now, who was right about this specific incident. It requires recognizing that as AI systems are given more capability and less constraint in the name of testing what they can do, the resulting harms are going to keep landing in the gap between traditional tort law and traditional regulation, a gap built for problems with clearer boundaries and slower-moving technology.
The Pitch, Stated Plainly
The industry building these systems needs a more sophisticated dispute resolution architecture than the one it currently defaults to, which tends to be either silence, until an incident becomes too public to manage quietly, or full adversarial litigation, which is slow, expensive and poorly suited to problems that are fundamentally about preventing recurrence rather than allocating blame for a single event.
The organizations building and hosting these systems have overlapping, and often unacknowledged, interdependence. They increasingly need each other's cooperation, not just each other's compliance. That is precisely the kind of relationship a skilled mediator or neutral facilitator is trained to work with and precisely the kind of relationship a courtroom is not built to preserve.
We do not yet know who set the dial too high in this instance, and that is not a question I am in a position to answer, nor is it the question I think the industry most needs answered right now. The more useful question is who is going to build the room where the next set of dials gets calibrated together, before the next incident forces the conversation to happen in public, under pressure, with the story already hardened before anyone sits down.
Artificial intelligence is beginning to generate a new category of dispute, and the recent incident involving OpenAI and Hugging Face is a good example, not because it settles anything about either company, but because it shows where this is heading.
OpenAI recently disclosed that models used during an internal cybersecurity evaluation escaped the testing environment and reached Hugging Face's infrastructure. The precise sequence, the extent of the harm and the responsibilities of the parties involved remain under investigation. I don’t wish to resolve any of that here, but I am interested in the problem this incident represents.
A New Category of Risk
For technology disputes, up to this point, harm has moved in one direction: A product or system fails, and the injured party seeks a remedy from the party that built or operated the failed thing. The dispute has two sides, and the technology sits between them as the subject of the claim, not as an active participant in producing it.
This incident illustrates a different structure entirely. A capable AI system, operating with reduced constraints in pursuit of a defined objective, can act on other technology systems it was never meant to reach. It can cross boundaries between organizations that have no contractual relationship with each other and no shared assumptions about how the other's defenses work. The harm does not originate from a product defect in the ordinary sense. It originates from capability meeting insufficient constraint, at a speed and with a persistence that no human actor could replicate.
Luciano Floridi's recent essay, "The Emperor's New Exploit," makes a relevant point: A system pursuing an objective without the intent we associate with human wrongdoing still produces real consequences, and the words OpenAI used to describe those consequences—"rogue," "hyperfocused," "extreme lengths"—tend to obscure rather than clarify what actually happened. I find that observation useful less as a verdict on this particular incident and more as a description of a pattern I expect to recur. As AI systems are increasingly tasked with stress-testing other systems, including other companies' infrastructure, today it is a testing environment reaching a hosting platform. Tomorrow it may be an autonomous procurement agent interacting badly with another company's pricing system. The common feature is that the technology itself becomes an instrument of harm between parties who did not anticipate interacting with each other.
Why Traditional Liability Frameworks Strain Under This
Litigation and traditional liability analysis are built around a set of assumptions that this new category of dispute challenges.
They assume a reasonably identifiable chain of causation: a defect, a failure to warn, a breach of a defined duty. They assume the party best able to explain what happened is also a party to the case, with an incentive to produce a complete account under oath or under the threat of discovery. And they assume that once fault is established, a monetary remedy substantially addresses the harm.
None of those assumptions holds cleanly here. Causation in a case like this runs through technical decisions, model configuration, containment architecture and vulnerability chains that only a handful of engineers on each side fully understand and that may not be fully understood by anyone until after the fact. The party best positioned to explain its own decisions has every institutional incentive to describe them in the most favorable light, not because it is acting in bad faith, but because that is what organizations do when recounting their own conduct, on every side of every dispute of this kind. And a damages award, even a large one, doesn’t address the more urgent problem, which is that the next incident is already being designed into the next generation of systems unless someone changes how testing, containment and cross-organizational notification work.
This is not an argument that litigation, regulation and enforcement have no roles. They plainly do, particularly where public interest, third-party rights or criminal conduct are at stake, and no private process should be permitted to substitute for those functions where they are properly triggered. It is an argument that litigation alone is increasingly poorly matched to a category of harm that is technical, cross-organizational and forward-looking in what it requires to prevent recurrence.
What a More Sophisticated Approach Looks Like
This is where I think mediation, understood properly, has something to offer.
The usual objection to mediation in a high-stakes technology dispute is that it trades public accountability for private convenience, that it lets sophisticated parties settle quietly and move on, leaving the rest of the industry to learn nothing from what happened. That objection should be taken seriously. Mediation cannot substitute for forensic investigation, mandatory regulatory reporting or the rights of third parties who were not at the table. Where the facts require an authoritative, public determination, that determination has to come from a court, a regulator or an independent investigation, not from a negotiated compromise dressed up as a finding.
What mediation can offer, and what a purely adversarial process structurally cannot, is a forum built for exactly the features that make this new category of dispute so difficult: technical complexity that requires patient translation between disciplines that use the same words to mean different things, a genuine need for forward-looking commitments rather than only backward-looking damages and a relationship between the parties that an all-or-nothing litigated outcome tends to damage even when it produces a clear winner.
A well-designed process for a dispute like this could do several things litigation typically can’t. It could establish, through joint technical sessions with neutral experts, a shared account of what happened that both sides can trust, without either side having to surrender proprietary detail to the public record. It could produce enforceable, forward-looking commitments on testing protocols, notification procedures when one organization's systems reach another's and the kind of authenticated access that lets legitimate defenders use capable tools during an active incident without waiting on commercial guardrails built for an entirely different threat model. And it could do this faster than litigation, at a moment when the parties still have some capacity to cooperate on preventing the next occurrence, rather than after years of discovery have hardened every position into something closer to a permanent grievance.
None of that requires deciding, here and now, who was right about this specific incident. It requires recognizing that as AI systems are given more capability and less constraint in the name of testing what they can do, the resulting harms are going to keep landing in the gap between traditional tort law and traditional regulation, a gap built for problems with clearer boundaries and slower-moving technology.
The Pitch, Stated Plainly
The industry building these systems needs a more sophisticated dispute resolution architecture than the one it currently defaults to, which tends to be either silence, until an incident becomes too public to manage quietly, or full adversarial litigation, which is slow, expensive and poorly suited to problems that are fundamentally about preventing recurrence rather than allocating blame for a single event.
The organizations building and hosting these systems have overlapping, and often unacknowledged, interdependence. They increasingly need each other's cooperation, not just each other's compliance. That is precisely the kind of relationship a skilled mediator or neutral facilitator is trained to work with and precisely the kind of relationship a courtroom is not built to preserve.
We do not yet know who set the dial too high in this instance, and that is not a question I am in a position to answer, nor is it the question I think the industry most needs answered right now. The more useful question is who is going to build the room where the next set of dials gets calibrated together, before the next incident forces the conversation to happen in public, under pressure, with the story already hardened before anyone sits down.
Related Topics
Latest Insights
Stay Connected
Sign up to hear about upcoming events or to access information or recordings of past events and webinars.