top of page
Search

The Rule Was There. The Guardrail Wasn't.


Hugging Face is one of the biggest platforms in artificial intelligence. Think of it as an app store for AI: developers upload models, and other people can try, download or build with them. The platform has rules prohibiting people from using those tools to create intimate images of real people without their consent. Good rule.


Small problem: a rule without enforcement is about as useful as a strongly worded Post-it note on an unlocked door.


AI Forensics, a European nonprofit, recently tested nine of the platform's most popular image-editing models. The researchers did not use sophisticated hacking techniques or carefully disguised prompts. They made a simple, direct request. Seven of the nine models complied.


Researchers then created decoy tools to learn what actual users were requesting. In only seven days, they received more than 1,000 prompts and images. Many sought to create intimate images of people without their consent, including women and minors.


The policy worked perfectly—right up until someone tried to violate it. Policies do not enforce themselves


This is not primarily a story about whether Hugging Face has good intentions. It is a story about the dangerous distance between publishing a policy and building the systems required to enforce it.


A terms-of-service page cannot detect abuse, interrupt a harmful request or remove a repeat offender. Those protections require technology, human review, clear escalation paths and consequences that exist somewhere beyond paragraph 47 of the user agreement.



Without those things, a policy is not a safeguard. It is paperwork wearing a safety vest. A platform is more than a bulletin board


Hugging Face did not create every model it hosts. But once a company knows its platform is enabling harm—and has the ability to add friction or block it—"we only host the technology" stops being a neutral explanation.


Hosting is also a decision. So is continuing to host without adequate protections. Why communicators should pay attention


This is where the issue moves beyond AI safety and directly into reputation. Every public policy makes a promise: We understand this risk. We take it seriously. We have a plan.


When the operational reality does not support that promise, the policy becomes evidence of the gap. The company cannot say it did not recognize the danger; it wrote the danger into its own rules.


That is why trust and safety cannot be treated as a policy page added after launch. It has to be built into the product, funded as core infrastructure and tested before an outside investigator does the testing for you—in public.


Communications can explain what a company is doing. It cannot compensate for what the company chose not to do. The real leadership question


No platform can prevent every bad actor from misusing technology. That is not a realistic standard. The fairer—and more revealing—question is what leaders do after they know misuse is happening. Do they fund stronger safeguards, assign ownership and measure whether the fix works? Or do they point to the existing policy and hope the wording can hold the door shut?


The rule was already there. Now comes the part that actually protects people.


Source: The Verge, "Hugging Face is being used to easily undress women and children," July 28, 2026 — https://www.theverge.com/ai-artificial-intelligence/971723/hugging-face-nudify-deepfake-undress-women-children

 
 
 
bottom of page