What a Supervisor Would Ask: A Reusable Information Request for Frontier-Model Containment Failures, Applied to the OpenAI–Hugging Face Incident
Kassi V. Assamoi
The July 2026 OpenAI–Hugging Face incident is the first publicly documented autonomous breach of a third party by an AI system. Public accounts conflict on facts needed to assess compliance. This project drafts a supervisory instrument the EU AI Office could use to test those accounts against evidence: an information request under Article 91 of the AI Act.
The instrument combines a reusable template organised around event roles rather than dates, a case schedule applying it to the OpenAI events, and a cooperative information request to Hugging Face. Sections distinguish statutory obligations, Code of Practice commitments and proposed supervisory practice; questions specify answer formats and supporting evidence. A conditional comparison across the EU AI Act, the Code, California SB 53 and New York’s RAISE Act identifies what must be established before reporting deadlines can be calculated.
Drawn from prudential supervisory practice, the instrument is a prototype with a worked application to the public record. It has not yet been tested with a respondent.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) What a Supervisor Would Ask: A Reusable Information Request for Frontier-Model Containment Failures, Applied to the OpenAI–Hugging Face Incident
},
author={
Kassi V. Assamoi
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


