True
Bessent (베선트) says that when an AI model is hacked, accountability rests with the management of the company that operates the model — not with the technology alone. The position treats a model breach as a failure of corporate governance, a reading underscored by a security incident at AI platform Hugging Face in which unauthorized access put secrets tied to users' models at risk.
Under Bessent's framing, an AI model is a corporate asset like any other. If it is compromised, the failure lies with the executives charged with safeguarding it — not solely with engineers, and not with the model itself. That makes model security a board-level concern: companies that build, host or serve AI models are expected to manage access controls, credentials and incident response as ordinary business risk, with the management team answering for lapses.
The reference point is a security incident at Hugging Face, one of the most widely used platforms for hosting and sharing AI models. Unauthorized access to the platform raised the possibility that secrets connected to users' deployed services were exposed. For operators, the episode showed how a compromise upstream still lands on the company running the model: rotating credentials, securing models and accounting to users fall to the operator's management, whatever steps the platform takes on its side.
For Korean companies in the AI market — from Naver and Kakao, which operate their own models, to enterprises adapting open-source models in-house — the message is direct. If a model is breached, the question will be who was responsible for preventing it, not merely what went wrong technically. Cybersecurity and AI policy in Korea fall under bodies including the Ministry of Science and ICT and the National Intelligence Service, adding a regulatory dimension to the management accountability Bessent describes.
Bessent's claim that hacking incidents involving AI models are the responsibility of the affected company's management is True.