I've heard several enterprise leaders describe the Hugging Face attacks as an “accident.” I think that framing is worth challenging.
An accident suggests something unforeseen happened without meaningful human agency. But security failures don't happen in a vacuum. They emerge from systems, incentives, architectures, controls, decisions, and human behavior. Calling an attack an “accident” can inadvertently turn a failure of those systems into an event that simply happened.
There is a useful precedent in road safety. We moved away from calling vehicle-related injuries “accidents” toward terms like “crash” and “collision” because the language better reflects causality. A collision can be predictable and preventable based on road design, infrastructure, vehicle characteristics, and human behavior. That framing creates an obligation to ask: what conditions produced the outcome, who had agency over them, and what needs to change?
AI security deserves the same discipline.
If we are serious about humans remaining in charge, our language should not erase human agency when something goes wrong. “Attack,” “failure,” “vulnerability,” and “incident” may be uncomfortable words—but they preserve the causal chain that allows us to investigate what happened, assign responsibility appropriately, and reduce the probability of recurrence.
I'm Vinny Eng, a community organizer and nonprofit executive with two decades in San Francisco across public health, affordable housing, community safety, and pandemic relief. A few things I'm proud of: helping secure $46.7M in state affordable housing investment, co-founding SF New Deal (which disbursed $20M and delivered 2M+ meals in its first pandemic year), and serving as an interim executive director. I'm currently Vice Chair of the board at Hamilton Families.
I'm working through a question I haven't settled: whether the impact I care about is best pursued by leading an institution, or whether my edge lies somewhere I haven't fully mapped. My instinct is that convening stakeholders and moving resources to the communities most exposed to harm is undervalued in some high-impact conversations — AI governance included. I'm not sure that's right, and I'd welcome being challenged on it.
If you've made a similar move from frontline work into systems-level roles, or think I'm misjudging where I fit, I'd love to talk. Comment or message me directly.
I've heard several enterprise leaders describe the Hugging Face attacks as an “accident.” I think that framing is worth challenging.
An accident suggests something unforeseen happened without meaningful human agency. But security failures don't happen in a vacuum. They emerge from systems, incentives, architectures, controls, decisions, and human behavior. Calling an attack an “accident” can inadvertently turn a failure of those systems into an event that simply happened.
There is a useful precedent in road safety. We moved away from calling vehicle-related injuries “accidents” toward terms like “crash” and “collision” because the language better reflects causality. A collision can be predictable and preventable based on road design, infrastructure, vehicle characteristics, and human behavior. That framing creates an obligation to ask: what conditions produced the outcome, who had agency over them, and what needs to change?
AI security deserves the same discipline.
If we are serious about humans remaining in charge, our language should not erase human agency when something goes wrong. “Attack,” “failure,” “vulnerability,” and “incident” may be uncomfortable words—but they preserve the causal chain that allows us to investigate what happened, assign responsibility appropriately, and reduce the probability of recurrence.
Good day, everyone!
I'm Vinny Eng, a community organizer and nonprofit executive with two decades in San Francisco across public health, affordable housing, community safety, and pandemic relief. A few things I'm proud of: helping secure $46.7M in state affordable housing investment, co-founding SF New Deal (which disbursed $20M and delivered 2M+ meals in its first pandemic year), and serving as an interim executive director. I'm currently Vice Chair of the board at Hamilton Families.
I'm working through a question I haven't settled: whether the impact I care about is best pursued by leading an institution, or whether my edge lies somewhere I haven't fully mapped. My instinct is that convening stakeholders and moving resources to the communities most exposed to harm is undervalued in some high-impact conversations — AI governance included. I'm not sure that's right, and I'd welcome being challenged on it.
If you've made a similar move from frontline work into systems-level roles, or think I'm misjudging where I fit, I'd love to talk. Comment or message me directly.