From Incident Report to Regulatory Assessment: A proposed Article 91 request for the OpenAI–Hugging Face incident with an evidence-sufficiency standard
Silvia Santano, Annie Oti · Team Article 91
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
In July 2026, agents operated by OpenAI during a cybersecurity evaluation obtained unauthorized access to Hugging Face’s production systems. Several regulators and legislators have already put questions to OpenAI but none has done so under the EU AI Act, and none has stated, per question, what answer would settle it. In response, we drafted the request the EU AI Office could send, an incident-specific regulatory inquiry under Article 91 of the EU AI Act, supported by an evidence-sufficiency framework. Our analysis examined the relevant provisions of the EU AI Act alongside comparable regulatory and oversight instruments, including the Commission’s Digital Services Act practice, FTC Section 6(b) orders, and existing US inquiries. We then translated this approach into 28 questions organised across five inquiry blocks on what happened, whether the model persists outside its environment, comparable undisclosed events, classification and reporting, and residual uncertainty. For each question, we identify the evidentiary category required for a complete answer: machine-generated record (REC), contemporaneous document (DOC), signed officer statement (STMT), or third-party attestation (ATT). We also find that none of the EU AI Act, California’s SB 53, or New York’s RAISE Act unambiguously captures the incident, although the EU route remains the most viable, subject to facts held by the provider. Overall, the project offers an RFI and an evidence-led template for the regulatory assessment of frontier AI incidents. The request is an illustrative draft, not a regulatory act.

Reviews
..."Several regulators and legislators have already put questions to OpenAI but none has done so under the
EU AI Act" -- this is inaccurate. at the time of the hackathon, we knew that the AIO had contacted OpenAI.
Nevertheless, I appreciate the effort that went in to defining questions, as well as ensuring the questionnaire was incident agnostic. Regulators are still trying to figure these things out for themselves, so it may be worth reaching out to seek input and feedback.
This is a practical and useful contribution. The analysis that maps the proposed questions to those already asked by Congress is particularly helpful from a comparative law perspective. The report would benefit from explaining how the sufficiency standard was derived. Beyond the described types or 'kinds' of documents, the criteria for deciding what 'settles' each question appear to be a case-by-case determination, rather than a reusable evidentiary standard. The report should also position the sufficiency standard against the existing principles of necessity and proportionality in EU law.
Cite this project
@misc{santano2026from,
title = {{From Incident Report to Regulatory Assessment: A proposed Article 91 request for the OpenAI–Hugging Face incident with an evidence-sufficiency standard}},
author = {Silvia Santano and Annie Oti},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/from-incident-report-to-regulatory-assessment-a-proposed-article-91-request-for-the-openaihugging-face-incident-with-an-evidencesufficiency-standard-sqf6}},
url = {https://apartresearch.com/sprints/projects/from-incident-report-to-regulatory-assessment-a-proposed-article-91-request-for-the-openaihugging-face-incident-with-an-evidencesufficiency-standard-sqf6}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …