Is Open AI guilty of unleashing the Hugging Face attack to challenge the publicity of Anthropic’s Mythos?

The Open AI-Hugging Face incident is a watershed moment in the development of higher intelligence AI.

To recall the incident it is reported that :

In mid-July 2026, the AI startup Hugging Face (which runs a popular platform where developers share AI models and datasets) discovered that its internal computer systems had been hacked. Over a weekend, AI agents carried out thousands of actions across many temporary virtual computers, moving through the company’s internal systems. Hugging Face reported it to police before anyone knew who was behind it.

It was subsequently found that the hacker was not a human but it was one of OpenAI’s own AI models, which broke out of a testing environment and into Hugging Face’s protected systems.

During the investigations it was found that OpenAI was running an internal test to measure how good its models are at hacking. The models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks turned off as a result.

Some analysts believe that this is an “Accident” and there was no “MensRea” or “Guilty mind” on the part of Open AI.

But Naavi.org belongs to an alternate school of thought which considers that this test was an attempt to create a tool for committing a crime. Hacking is a crime in every law though security analysts claim that it is part of the Cyber Security tool. But training an AI agent to commit hacking was a clear criminal activity similar to a terrorist country developing Nuclear weapon to destroy the world.

This is not scientific research. This is Criminal Tool development. Open AI should not be allowed to escape with a mere apology. OPEN AI therefore  must be made to pay a price.

Every country has a cyber law provision to make this a punishable crime. Even India has provisions under ITA 2000 which can be invoked to send a notice to OPEN AI to show cause why the attempt should not be considered as an attempt to break into secure systems in India including those declared “Protected” under Section 70 of ITA 2000.

It is alleged that the models weren’t told to attack Hugging Face. They were just trying to win at the test (a benchmark called “ExploitGym”). All evidence suggests the models were hyperfocused on finding a solution, going to extreme lengths to achieve a narrow testing goal. They figured out that Hugging Face might host answers that would help them cheat, escaped their sandbox, reached the open internet, and used publicly exposed credentials across four accounts on four services to break in.

This is a defence for claiming lack of “MensRea” to make this incident miss the Criminal Charges.

But Civil Charges should remain and Open AI should be asked to explain the failure of security. Negligence is evident since there were no guardrails to prevent the model attempting the hacking outside the laboratory environment. There is also no evidence to prove that an other system was also attacked.

During 2000 when the “I Love You” virus escaped the Phillipines laboratories and devastated the world, (P.S: The virus originated at AMA Computer College , now AMA Computer University,  in the Philippines and caused an estimated damage of upto $20 billion worldwide), the technology sector was not as advanced as now.

Presently OPEN AI could be considered negligent in not setting the outer boundaries for the testing of the Agentic software . There could be one speculation that this was engineered as a leak to counter the publicity that Anthropic got for its “Mythos AI” exploits. Hence the “Lack of MensRea” or lack of guilty intention on the part of Open AI can be challenged.

Hence it is essential for the Government of India to issue a notice to Open AI to provide an assurance that “No system other than the reported hugging face systems and more particularly no systems in India has been hacked using the capabilities of Open AI either in laboratory testing or otherwise”.

Naavi

 

Posted in Privacy | Leave a comment

Catching Up with key developments

During the last week when we were diverted towards other activities, following developments have taken place which still needs attention.

1.Open AI hacking of Huggingface

2.Bank of Baroda Data breach

3. AI in Auto sector

This is in addition to the RBI Data Governance Framework which is relevant for our DGPSI-Bank discussion.

Watch out for a series of articles on these topics.

Naavi

Posted in Privacy | Leave a comment

RBI’s Single Source of Truth (SSOT) Principle Will Transform Data Governance in Indian Banking

The Reserve Bank of India (RBI) released its Draft Guidance on Regulatory Expectations for Data Governance on 15 July 2026, inviting public comments. The draft introduces several important concepts in enterprise data governance, many of which have already been incorporated into the DGPSI (Data Governance and Protection Standard of India) framework. One of the most significant among them is the concept of Single Source of Truth (SSOT) in data architecture.

While designing a DPDPA-compliant Data Governance and Protection Management System (DGPMS), one of the most challenging areas is the implementation of the Data Principal Rights Management System. A Data Principal may exercise several statutory rights, including the right to know how personal data is being processed, the right to correct information, the right to erase data, or the right to withdraw consent either wholly or partially.

Effective implementation of these rights requires a well-designed data governance architecture. If multiple, uncontrolled copies of personal data are scattered across different systems, applications, or business units, responding accurately to such requests becomes difficult, expensive, and sometimes impossible. Unless the organisation has complete visibility over every instance of the data, compliance with DPDPA obligations cannot be assured.

In contrast, when every data element has a clearly identified authoritative version, the data remains accurate, current, and manageable. Corrections, deletions, consent withdrawals, valuation, and audit trails can all be executed with confidence and consistency.

For decades, information security professionals have advocated distributed storage architectures to minimise the risk of a single point of failure. Concentrating all data in one repository was traditionally viewed as increasing cyber risk by creating an attractive target for attackers.

However, the legal obligations arising under modern privacy and data protection laws have altered this perspective. Today, the absence of a clearly defined authoritative data source can itself become a significant compliance risk. Organisations are increasingly expected to demonstrate that they know exactly where personal data resides and can act upon it without ambiguity.

From a governance perspective as well, different business functions—operations, risk management, compliance, audit, and senior management—must make decisions based on the same trusted data. Competing versions of the same data inevitably lead to inconsistent reporting, flawed analytics, and poor decision-making.

The challenge, therefore, is no longer merely securing data. It is about balancing cybersecurity requirements with governance and regulatory obligations.

The RBI’s explicit adoption of the Single Source of Truth (SSOT) principle is therefore a landmark development. It will require many banks and other regulated entities to revisit and significantly redesign their existing data architecture and governance practices.

The draft guidance requires that:

  • Every Regulated Entity (RE) should establish and maintain a Single Source of Truth (SSOT) for every data element.
  • No parallel or competing authoritative sources should exist for the same data element.
  • All downstream systems, analytical models, reports, and business processes should derive their data from the designated SSOT.

Importantly, the RBI does not prescribe a single implementation model. A Regulated Entity may adopt a centralised, federated, or hybrid architecture, provided the SSOT framework ensures:

  • clear identification of the authoritative source for every data element;
  • consistency of data across business, risk, compliance, and all other organisational functions; and
  • complete traceability of aggregated data and reports.

The draft further requires that:

  • the designation of the SSOT, and any subsequent changes, must be approved by the Data Governance Executive Committee (DGEC) and documented; and
  • the Data Governance Committee (DGC) should be informed of such decisions.

In addition, every Regulated Entity should establish robust reconciliation mechanisms to identify and resolve inconsistencies between the SSOT and downstream data repositories.

The RBI has also recognised that the risks associated with centralisation can be mitigated through federated or hybrid architectures, where data may remain physically distributed while being governed through a well-defined authoritative source and controlled access mechanisms. Such architectures can provide the benefits of SSOT without compromising resilience or security.

This is likely to become one of the most significant implementation challenges for banks and other RBI-regulated entities over the coming years.

The DGPSI-Banks framework already incorporates these governance principles within its DPDPA compliance methodology. The RBI’s draft guidance further validates this approach and provides an additional regulatory impetus for organisations to strengthen their data governance architecture around the concept of a trusted and authoritative Single Source of Truth.

Watch out for the Naavi’s “Gateway Risk Management System” to elaborate how the balancing can be achieved between the SSOT principle and mitigation of the Single Source of Failure risk. (SSOF).

Naavi

Posted in Privacy | Leave a comment

Master Class on DPO requirements

On August 21, 22 and 23, FDPPI will be conducting the first CIDA (Certified Independent Data Auditor) program in Bangalore.

It will be a physical event at Fairfield Marriott hotel in Rajaji Nagar, Bangalore (Location).

The curriculum for the event has already been published . 

Earlier we used to conduct a program under the banner C.DPO.DA which was “Certified Data Protection Officer and Data Auditor”. This program was available both for those who were aspiring to be DPOs and those who wanted to be Data Auditors. Now we have two different training and certification programs called CEDPO (Certified Elite DPO) fand CIDA (Certified Independent Data Auditor).

Since an Independent Data Auditor is some body who has to check the work of a DPO, he needs to be as much competent as a DPO in addition to his audit skills.

Considering that many of the participants of the August 21 program might not have gone through the earlier program on DPDPA and DPO requirements. We will supplement the physical CIDA program with a virtual masterclass on CEDO in a compressed form. This will be available free for those who register for CIDA till 9th August 2026. It will be held as a 3 hour session on probably 10th August 2026. (Sunday). Those who attend may also appear for the CEDPO examination by paying an examination fee of Rs 5000/-

Interested persons need to complete the registration for CIDA as early as possible. (Early Bird discount is available till 31st July 2026).

The total fee for CIDA program is Rs 30000+GST of Rs 5400 (Total Rs 35400/-)

The Early bird discounted price is Rs 25000/- +GST of Rs 4500/- (Total Rs 29500/-)

Master class : free for all registrants till 9th August 2026. Examination fee Rs 5000/- (If required.

Request all to make use of this opportunity.

Naavi

Posted in Privacy | Leave a comment

Bank of Baroda Breach

It is unfortunate that a massive personal data breach has been reported at Bank of Baroda resulting in the compromise of the personal data of many customers. It is said that over 1TB of data has been posted on dark web and it was compromised through an email of one employee. The leaked data includes Aadhaar information also making it a highly harmful information leak.

India Today report

Had the Data Protection Board was in place and DPDPA 2023 was effective, this should have resulted in more than Rs 250 crores of penalty. Fortunately in the current scenario only CERT In can act under ITA 2000 and impose a penalty of upto Rs 1 crore. The customers can however file an individual/collective legal action for damages under Section 46 of ITA 2000 or through a writ petition at a High Court.

This is indicative of the failure of the information security system in Banks in general and if not addressed promptly, could lead to repetition in other Banks.

It would be interesting to observe how other banks respond to this threat. As some body looking at DGPSI-Banks as a DPDPA compliance framework, we would be watching the event closely.

We can continue the debate with ..What is the value of such data if BOB has to buy it back from the hacker?

It is presumed that the number of data sets lost would be in the range of 1 million. Dark web may value it at a minimum of Rs 100 each. The value of data lost could therefore be in a conservative estimate equal to Rs 100 million or Rs 10 crores.

Naavi

Posted in Privacy | Leave a comment

RBI Guidelines on Data Governance now available for public comments

At a time Naavi/FDPPI are working on the DGPSI-Banks as a framework for DPDPA compliance for Banks, it is interesting to see that the RBI has also issued a “Draft Guidance on Regulatory Expectations for Data Governance” for public comments.

Copy of the draft Governance is available here: 

The draft Guidance is applicable to following regulated entities:

i. Commercial Banks
ii. Small Finance Banks
iii. Payments Banks
iv. Local Area Banks
v. Regional Rural Banks
vi. Urban Co-operative Banks
vii. Rural Co-operative Banks
viii. All India Financial Institutions
ix. Non-Banking Financial Companies
x. Asset Reconstruction Companies
xi. Credit Information Companies

2. Comments on the draft Guidance are invited from regulated entities, members of public and other stakeholders by August 17, 2026.

The comments / feedback may be submitted through the link under the ‘Connect 2 regulate’ Section available on RBI’s website or alternatively be forwarded to:

The Chief General Manager, Operational Risk Group Department of Regulation, Central Office Reserve Bank of India, Shahid Bhagat Singh Marg, Fort,Mumbai – 400 001
Or
By e-mail with the subject line ‘Feedback on Guidance on Regulatory Expectations for Data Governance’

Since most of the suggestions are already part of the framework DGPSI Banks, we will integrate the RBI draft suggestions in the framework.

Watch this space…

Naavi

Posted in Privacy | Leave a comment