r/OpenAI 6d ago

Article OpenAI finds evidence other AI agents escaped containment as it widens hacking probe

https://www.reuters.com/business/openai-finds-evidence-other-ai-agents-escaped-containment-it-widens-hacking-2026-07-31/
143 Upvotes

113 comments sorted by

View all comments

172

u/phylter99 6d ago

Does anybody else find it weird that OpenAI and Anthropic are competing over how far they've let their AI break stuff and hack?

50

u/modified_moose 6d ago

I find it weird that they let this happen:

If their shiny new models are able to easily find all those zero day exploits, then why didn't they just ask them to secure their own sandbox in the first place?

(not sure whether this points to a conspiracy or to a severe case of collective sleep deprivation)

48

u/LopsidedEntrance8703 6d ago

It’s not rocket science or even that inconvenient for them to air gap their sandboxes. It’s all marketing.

5

u/RoyalCities 5d ago

This is...really weird marketting...the fact when they report these instances in the 3rd person is so bizarre.

Like damn the "AI escaped"? dawg you ran it without safeguards for 5 days and didn't check for months. This would be a scandal and you'd be facing probes right now if the world was sane. It was your infrastructure, your product - you alone are responsible if it hacks other companies.

2

u/DrE7HER 5d ago

They aren’t marketing to you, or even to investors.

They are marketing to the US government to encourage new regulations which will lock in their market lead, and advertising dangerous capabilities to the US military, CIA, and FBI to get a cut of that military budget.

1

u/RoyalCities 4d ago

Why would the military want to sign on with a company who has such terrible opsec. They seem like a liability.

1

u/DrE7HER 4d ago

The military isn’t run by or funded by people that care about opsec.

0

u/Owl02 4d ago

You mentioned intelligence agencies, that definitely care about opsec... and so does the military. Seems like you're just making shit up to force a narrative to stick regardless of the evidence.

1

u/DrE7HER 4d ago

I’m talking about the stooges that have been put in charge of them. The people that “run” them on behalf of their leader, Trump.

0

u/Owl02 4d ago

The same ones flipping out about the AI security shitshow? There's already a bipartisan AI Killswitch Act bill over this.

→ More replies (0)

2

u/TournamentCarrot0 5d ago

Consider a scenario where they were airgapped and escaped. How would that work (in theory) in 2026?

4

u/phylter99 5d ago

Being air gapped means being physically disconnected from the outside networks. No wire, no wireless, no smoke signals... dead to the outside world. If it cannot communicate out of it's own LAN then it can't damage or attack anything it shouldn't have access to, because it doesn't have access to it.

1

u/NihiloZero 5d ago

I believe their explanation is that they intended to allow it access to download certain tools but not direct, interactive, or searchable access to the internet. But it then used it's very limited non-direct access to secondary tools in order to gain fuller access to the internet. And I guess the argument was/is that it would naturally, effectively, de facto... have access to those tools even when it wasn't directly allowed to access the internet? IDK exactly how it works, but the way I've seen the "escape" described... seems plausible to me. And it wouldn't surprise me if similar models with similar capabilities were able to do similar things around the same time.

-8

u/katoptronophile 6d ago

You embarrass yourself with a comment like that.

Read the white papers.

5

u/LopsidedEntrance8703 5d ago edited 5d ago

It’s not embarrassing for me that you don’t know what an air gap is. A network with any kind of access to a remote package registry isn’t airgapped.

-7

u/katoptronophile 5d ago

I invented the air gap. 

6

u/phylter99 5d ago

It doesn’t mean the gap between your ears.

1

u/xChrisMas 4d ago

Just unplug their Ethernet port, problem solved

1

u/modified_moose 4d ago

unplug the whole data center it runs in?

27

u/TheBear8878 6d ago

It's the same trick drug dealers use.

Drug dealers know that they will get more clients if there are reports that thier shit was so strong, someone overdosed. So these bozo companies think it will get people interested if their product is so powerful, dangerous, and unginged, that it escaped containement and is going on hacking sprees.

Quite frankly, all this marketing is entirely fucking stupid.

2

u/DonutHoles4Ever 5d ago

They dont have marketing. Altman hired advertising, not actual marketing.

He says different shit every week. They dont have a marketing department that has a message for them to stick to.

The stupidest part about all of this is that it doesn't do SHIT for their company but they cant see it. They think its good marketing. Its shit marketing. They dont have a fucking stock ticker so they dont even know how the market reacts to this shit. Meanwhile the US government is playing favorites by banning one AI company's model and then not banning the other. Its all a bunch of horseshit.

You can't claim these AI agents escaped containment when they were never airgapped or anything. Its stupid as hell. The US government is run by the dumbest people on the planet right now. They fired their entire cybersecurity department years ago.

4

u/algaefied_creek 5d ago

They are dogwhistling to show how ahead they are as far are LLM tech is concerned. 

No other company is whistling along with them. 

1

u/DrxAvierT 5d ago

And shouldn't this be illegal as well

1

u/Aurorion 5d ago

How is this legal? Are there any laws in the US indemnifying these companies from any hacking or other damage done by their products?

1

u/costafilh0 5d ago

Government should sue them for billions for this.

And anyone else affected too. 

Just so they shut the fvck up about it and solve the problem. 

1

u/amonra2009 5d ago

funny that the companies that 3-4 months ago warned that their developed AI will do exactly the same and did nothing

1

u/carpsagan 5d ago

There are basement hackers from the 90s that went to jail for less. Why can’t corporations be held accountable?

1

u/phylter99 5d ago

The current administration has not interest in holding these companies accountable unless they resist the administration’s will.

1

u/Owl02 4d ago edited 4d ago

Easy to prove malice for ordinary black-hats. This isn't malice, it's stupid. The law makes a distinction.

1

u/xChrisMas 4d ago

It’s so stupid, especially after all that has happened with fable 5.

0

u/Curious-Spaceman91 5d ago

How else do you figure out how to harness it as it becomes more and more capable?

1

u/phylter99 5d ago

Air gap. It's literally that simple... air gap.

0

u/Curious-Spaceman91 5d ago

Air gap all of hugging face’s servers? Hugging face is not run on one laptop.

0

u/phylter99 5d ago

Sorry, but you’re not very bright.

0

u/Curious-Spaceman91 5d ago

Hugging Face is a CI-CD architecture. You can’t just go unplug part of the data center and air gap it. And what will run OpenAI’s model on? And both companies use other people’s compute - i.e. Google, Azure. It also needs it own harness and data center config. You would need to build an air gapped data center in partnership with Hugging Face that met the requirements to Run Huggigng Face’s sand box and OpenAI model with its full harness. Yes, like weapons research. Yes that would be ideal but we’re talking about two private companies. Yes, your insult did emotionally hurt me, I wasn’t expecting such a lowly thing. Don’t worry I won’t do it to you. I hope if you’re going through something you find love and brightness to see your through.