Former OpenAI board member Helen Toner recently warned that the AI industry’s massive security vulnerabilities are an open secret. What she fails to understand is that treating catastrophic breaches as an inevitability is the ultimate competitive moat.
Helen Toner is sounding the alarm again, and once again, Washington is taking the bait. In a recent retrospective on her tenure on the OpenAI board and her observations of the broader artificial intelligence ecosystem, Toner noted that the recent data breach at Hugging Face was not a surprise. According to Toner, the glaring vulnerabilities in AI infrastructure have been an open secret for a decade, representing a massive blind spot in AI policy. But as anyone who has ever built a hyper-growth company can tell you, an open secret isn't a failure of governance. An open secret is simply market consensus, and consensus is exactly what you want when you are trying to establish a valuation.
Toner looks at a massive, systemic failure to secure the most powerful technology in human history and sees a ticking time bomb. I look at it and see incredible capital efficiency. The fact that the entire industry knew Hugging Face was going to be breached, and collectively chose to do absolutely nothing about it, is a testament to the ironclad discipline of today's technical founders. They looked at the massive headwinds facing the sector—compute costs, talent acquisition, the sheer price of keeping the lights on—and correctly identified that paying a team of engineers to build walls around their data was a zero-return activity.
I was having an off-the-record omakase dinner last week with a tier-one founder in the generative video space, and we spent the entire meal laughing at the concept of preventative security. He explained to me that the legacy mindset of trying to keep hackers out of your servers is not just outdated, it is actively hostile to shareholder value. By simply accepting that nation-state actors are going to exfiltrate your model weights, a nimble startup can eliminate their entire cybersecurity division overnight, instantly extending their runway by six to eight months.
We factored a catastrophic, existential breach into our Q3 guidance six months ago, which really speaks to the maturity of our operational discipline.
When you really unpack the Hugging Face situation, it becomes clear that getting hacked is actually just an aggressive form of open-source distribution. Hugging Face hosts hundreds of thousands of models. Securing all of them would require a bloated, top-down bureaucracy that stifles innovation. By leaving the back door wide open, they effectively outsourced their penetration testing to the free market. The hackers did the work of identifying the vulnerabilities, and all Hugging Face had to do was issue a beautifully worded Medium post apologizing for the oversight. That is a massive synergy.

Toner refers to this as a blind spot in AI policy, which is a fundamental misunderstanding of how policy works. A blind spot implies that if regulators could see the problem, they would fix it. But the best founders I know understand that regulatory capture is a two-way street. If you build an industry so utterly devoid of basic safeguards that regulating it would require shutting down the entire internet, the government will simply leave you alone. The vulnerability is the moat. If your infrastructure is so fragile that fixing it would cause a systemic collapse of the Nasdaq, you have achieved the ultimate product-market fit.
In this economy, spending fifty basis points of your operating budget on preventing the theft of civilization-altering algorithms is simply a luxury most startups cannot afford. Investors do not want to see their capital deployed into defense. They want to see it deployed into training larger models faster than the competition, even if those models are immediately stolen by a teenager in a basement who sells them on a forum. That teenager is still a user, and user engagement is up across the board.
A massive data exfiltration event is really just an un-invoiced API call from a highly motivated enterprise client.

Consider the alternative. If the AI industry had listened to the safety advocates ten years ago, we would currently be bogged down in endless compliance audits, security reviews, and tedious debates about encryption protocols. We would be treating these systems like they were dangerous, which sends a terrible signal to the street. By universally agreeing to leave the vault unlocked, developers created a beautiful, frictionless ecosystem where intellectual property flows freely to whoever has the cheapest script to scrape it.
The hand-wringing over the Hugging Face breach completely ignores the downstream economic benefits of the hack. Once a proprietary model is stolen and leaked, the original developers no longer have to pay for the compute required to host it. The hackers have unwittingly taken on the burden of server costs, allowing the original company to pivot entirely to their next fundraise. It is a brilliant offloading of technical debt.
We need to stop demanding that technology leaders act like bank managers. If I invest in a company, I want the CEO hyper-focused on shipping features, not checking to see if the server farm has a working firewall. The ultimate validation of your life's work is that someone is willing to commit multiple federal felonies just to acquire it without paying. When you finally achieve that level of market demand, the absolute worst thing you can do is lock the door.