Who Pays When Someone Else's AI Model Fails

A Hugging Face breach exposed the real risk of ready-made AI models: not the code, but who trained it and who's accountable when it fails.

Agnessa Tomashevska ZentixSoft

Agnessa Tomashevska

CEO at ZentixSoft

Who Pays When Someone Else's AI Model Fails

Who Pays When Someone Else’s AI Model Fails

An op-ed column by Agnessa, CEO of ZentixSoft

Breaches usually make headlines when money or personal data is stolen. The recent incident at Hugging Face — the platform half the world pulls ready-made AI models from — was about something else. Nobody broke into a customer database. What got broken was trust in a product that companies now build straight into their core processes, often without ever asking who assembled it or how.

Which brings up an uncomfortable question worth sitting with: if a model you downloaded from someone else’s repository misbehaves tomorrow, who is actually responsible?

The Convenience Nobody Audits

The industry treats ready-made models the way it treats an npm or pip package: find it, plug it in, move on. Nobody reads a library line by line before using it — and the same habit has carried over to models. Whatever answers test prompts well enough goes straight into production.

The problem is that a model isn’t a library. It’s a black box of billions of parameters, trained by someone you don’t know, on data you can’t see, with vulnerabilities you have no way of spotting in advance. When a repository turns out to be compromised, or a model turns out to hide unwanted behavior, companies find out from the news — not from their own audit. This has already happened. It will happen again.

The second layer of the problem is the supply chain. You’re not trusting one company — you’re trusting everyone who touched the model before it reached you: whoever trained it, whoever hosted it, whoever fine-tuned it along the way. Every link is a place where something could have gone wrong, and none of them answers to you personally.

Ukrainian Business Has Asked This Question Before

For the Ukrainian market, questioning trust in someone else’s infrastructure isn’t an abstract idea pulled from a tech digest — it’s been daily practice since 2022. Businesses here learned early to ask “what happens if this service goes down, gets compromised, or ends up controlled by the wrong people” — it just used to be about cloud servers, and now it’s about AI models.

The same instinct that pushed companies to duplicate communication channels and back up critical data now applies to a new question: can we explain where the model making decisions inside our product actually came from? Who has access to it? What happens if the provider disappears from the market tomorrow, or ends up under sanctions, or gets attacked?

This isn’t paranoia. It’s the same “verify before you rely on it” reflex Ukrainian business built earlier than most — and it’s quickly becoming the standard for anyone who takes AI seriously.

A Sober View: Where the Real Risk Is, and Where Just a Scare Story

Not every company using a ready-made model is at risk. A startup plugging a public API into a website chatbot risks its reputation at worst — not its critical infrastructure.

The question gets sharp where AI makes decisions with real consequences: system access, financial processing, medical recommendations, automation in regulated industries. That’s where three questions are worth asking:

  • Do we actually know who trained the model we’re using, and how? If the answer is “no,” that’s not automatically a problem — but it’s a risk worth being aware of, not ignoring.
  • What happens to our product if the model or its provider disappears or gets compromised tomorrow? If the answer is “everything stops,” you don’t have a backup plan — you have a dependency dressed up as a tool.
  • Do we have any way to check the model’s behavior independently of the vendor’s word? Auditing, testing against our own edge cases, monitoring for anomalies — anything beyond taking it on trust.

The Bigger Picture

The first wave of AI adoption was about speed: plug in a model, show a result. The second wave is about accountability: who stands behind that model, and what you do when the trust turns out to be misplaced.

Businesses already used to asking these questions about their own infrastructure are starting to ask them about AI too — not out of fear, but without blind trust either.

This isn’t about being scared of ready-made models. It’s about knowing exactly who you’re trusting the moment you hit “connect.”

Get a consultation

Agnessa Tomashevska ZentixSoft

Agnessa Tomashevska

CEO at ZentixSoft

I'm the founder and CEO of ZentixSoft. My team builds custom software that delivers real business impact — blending technology with strategy to turn bold ideas into high-performing products.

Browse all articles