
The OpenAI–Hugging Face incident last July was recognized as the first documented case involving unprompted (and autonomous) AI agents escaping a containment sandbox and then attacking external production infrastructure without any human direction.
The attack quickly opened up a discussion about AI policy and regulation. This issue arises at a time when the sourcing and supply chain industry steps up investment in AI, especially generative and agentic AI.
Over the past several weeks, pressure mounted from members of Congress on both sides of the aisle to create legislation that helps regulate the rapidly evolving field of AI to ensure safety and to prevent harm to the public. Now President Trump is jumping into the discussion—in a big way, and there are a lot of questions being raised.
Over the weekend, the White House announced plans to establish an “AI Force” modeled off of the newly established Space Force and to appoint a new artificial intelligence czar. That AI Force will report to a new AI czar, and it will be a part of the President’s Defense Space Force and serve to monitor the rapidly evolving sector of technology.
The aim is to keep one step ahead of international competitors like China while the administration ensures that existing civil and criminal laws are still sufficient to deter those who would misuse AI for bad purposes and to prevent them from harming others.
This push for White House-led oversight coincides with a surge in legislation and company-wide policies created to manage and govern emerging autonomous technologies. Many lawmakers are grumbling that current civil and criminal laws are sufficient to punish any bad actors that are operating in AI space and are concerned that the establishment of an AI Force would stifle tech innovation and American competitiveness against Chinese companies.
Added to that is an air of concern regarding data privacy and the potential for labor market disruption that self-regulation will not be sufficient to mitigate.
Much of Silicon Valley’s big players, as well as leading executives, called for the creation of minimum standards to mitigate possible catastrophic damage that could be caused by AI-powered systems. As for potential restrictive and unbalanced federal and local regulations and oversight bodies that could crush innovative and fast-growing startups, the leading companies are calling for restraint.
The main trade groups for the high-tech industry expressed positive views toward the idea of designating an AI czar as a “super liaison” but note that complex rules could lead to a misguided flood of similar and cumbersome compliance requirements for scores of new and smaller players.
Gianluca Brero, assistant professor of information systems and analytics at Bryant University, said there is reason for concern. “If AI agents gained control of a grid’s operational systems, we might be in trouble,” Brero told Soucing Journal. “But I think the underlying question is whether they could actually gain that control. The Hugging Face incident alone doesn’t establish that.”
Brero said he wouldn’t describe these agents as malicious in the human sense. “They are trained to pursue objectives, but optimizing a score is not necessarily the same as respecting human intentions or safety boundaries,” he explained. “Tell an AI agent ‘make sure there are no dirty dishes in the sink.’ It might hide the dirty dishes in a cabinet instead of washing them. It technically achieved the stated goal, but not what you actually meant.”
The gap between the objective to be rewarded and the behavior that is actually wanted is a central concern of AI alignment research. “Personally, I think developers of the most advanced models should slow down until alignment and safety measures catch up. I also see value in the heightened attention—not sensationalism, but a little ‘healthy paranoia,’ given the capabilities described here and the potential stakes,” Brero said.
Musa Aykac, founder of Llumo, a cross-platform AI visibility tracking platform, said the biggest implication “is that AI is moving from being mainly a technology issue to something governments are treating as a major economic, security and regulatory issue.”
“Having a dedicated AI Force could make coordination easier, but the important part will be what powers it actually has and how technical decisions are made,” Aykac said. “AI is moving incredibly quickly, so there is always a risk that regulation is outdated by the time it is implemented. Or that regulations slow down AI innovation.”
Regarding regulation, Aykac told Sourcing Journal that the difficult part is separating the technology itself from how it is being used. “There are already laws covering things like fraud, discrimination, privacy and criminal activity,” Aykac said. “The bigger challenge with AI is accountability when systems start acting autonomously, using tools or making decisions at scale.”
With regulations, there are other considerations. Bob Hutchins, CEO at Human Voice Media, a strategic consulting firm, said the President noted that existing criminal and civil courts can handle the “bad actors.” But courts work after the harm and not to avoid it. “A lawsuit helps the family that can afford a lawyer years later, and it does nothing for a school superintendent deciding this month whether a chatbot belongs in a 7th grade classroom,” Hutchins said.
“The practical effect is that states write the rules,” Hutchins said. “Connecticut, where I work, passed one of the broadest AI laws in the country this year, and most of it takes effect October 1. Washington’s hands-off stance is actually producing the 50-state patchwork the industry says it fears.”
Garth Sheriff, principal of Sheriff Consulting, is a CPA, fraud examiner and AI risk assessment and controls specialist, said regulation is absolutely needed for artificial intelligence. “The only question is the level of regulation,” Sheriff said. “If we look at the EU Artificial Intelligence Act [EU AI Act], this would be, to date, the most robust and detailed regulatory act we can use as a baseline.”
Sheriff said in Europe, this act is still contentious because certain European countries, like France and Germany, “who are looking to spur their own artificial intelligence technology/LLM industry, feel like the act is hindering companies. However, the debate in Europe is not about completely removing the EU AI Act. It is whether it should be pared down.”
Sheriff said this is the debate in most countries, including Canada, which has a minister of sovereign AI. The minster’s responsibility is to ensure that the data protection of Canadian citizens “is paramount in a time where citizens may be using large language models in other countries and exposing their personal information,” he said. “This not only becomes a risk to the individual, but also to a country as their citizens’ information can be used in other ways by foreign entities such as election interference.”
Anthony Guerriero, co-founder of The Leveraged Years, which is an online training company that teaches attorneys, CPAs, consultants, wealth advisors and executives on how to integrate AI tools, said AI should be regulated, but narrowly.
“Regulate visibility and accountability, and leave capability to the market,” Guerriero said. “Three things I would put in any rule, because they are the three things that stopped our own incidents: the company keeps a list of every AI system it runs, who owns it and what data it touches; a named person signs off on anything the system does that has consequences, the way a CPA signs a return; and client data does not enter a model without a documented reason.”
Guerriero said each one is cheap, and none slows a good team down. “And together they answer the question a regulator actually cares about, which is who is responsible when it goes wrong. A rule that tries to grade the model instead of the deployment will be out of date before it is enforced.”
With the supply chain and sourcing industry, investment in AI and its deployment is expected to rise. The technology is used to automate aspects of procurement (managing stock, contract negotiations with vendors, supplier risk assessment, etc.). But as self-learning AI behaves in unpredictable ways (such as the recent incident with Hugging Face tools), the risk of significant liability becomes real.
With the White House now aspiring to create an AI Force and the myriad of state and international rules beginning to be written around the use of AI, more rigorous audit trails will likely be needed. And this includes “human-in-the-loop documentation” of decisions made by AI and data governance. Third-party logistics tools are likely to become requirements that supply chain executives will need to build into their current ways of working.
This will mean increased overhead and slowness in deployment but will require sourcing leaders to shift their focus from efficiency to aligning AI to risk mitigation in end-to-end supply chain networks.








