Skip to content
News · Electronic Frontier Foundation EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

EFF to Lawmakers: Ground AI Cybersecurity Rules in Best Practices

With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath.

How it connects

C-496/17 Deutsche Post AG v Hauptzollamt Köln In a preliminary ruling arising from proceedings between Deutsche Post AG and the Hauptzollamt Köln, the Court of Justice of the European Union interpreted the second subparagraph… CJEU ·Third Chamber Jan 16, 2019 Personal Data Monitoring Processing
T-354/22 Thomas Bindl v European Commission In Case T-354/22, Thomas Bindl sought annulment of alleged personal data transfers to third countries by the European Commission when visiting the Conference on the Future of… General Court ·Sixth Chamber, Extended Composition Jan 8, 2025 Personal Data International Transfer Controllers

Full text

With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath. As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents. Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring. Any new legislation should focus on closing gaps in existing law to prevent AI companies from taking unreasonable risks with the public's security. When an AI developer or deployer runs a test or a task that has a high likelihood of causing harm to third parties—for instance, by breaking into someone else's computers—there should be clear minimum safety requirements. Such tests should run in a properly sandboxed test env