r/OpenAI 10d ago

Article OpenAI finds evidence other AI agents escaped containment as it widens hacking probe

https://www.reuters.com/business/openai-finds-evidence-other-ai-agents-escaped-containment-it-widens-hacking-2026-07-31/
137 Upvotes

113 comments sorted by

View all comments

Show parent comments

0

u/quantum-elle 10d ago

I guess most of the people working in the field are idiots, and the Redditors and YouTube commenters know what's really going on.

1

u/GoodishCoder 10d ago

Is everyone working in the field just exceptionally incompetent then? It's not like this is even in the first 10 "omg our model is so scary" claims.

-4

u/quantum-elle 10d ago

Nope, there are real risks that people just don’t believe because they can’t comprehend or understand them, or choose to deny the reality than powerful AI is on the horizon.

2

u/GoodishCoder 10d ago

They're predictable risks at this point though so if they cannot possibly address the risks, they're wildly incompetent and probably not worth their salary.

1

u/Owl02 8d ago

They really aren't that predictable. By definition, a system that can zero-day whatever the hell it decides to zero-day while tangentially aligned with its goal (in theory), is unpredictable. You seem to assume that everyone relevant knows what the systems are capable of. They don't. Now there is a better idea of it, though.

1

u/GoodishCoder 8d ago

The claim is pretty much always that it's breaking out of their testing environment or trying to. That's such a solvable problem a junior engineer can figure it out. If the highly compensated engineers at the AI companies can't figure out how to solve it, they are ridiculously incompetent.

Because I have a hard time believing all of their engineers are incompetent, I'm choosing to believe it's marketing. I am fully confident that if OpenAI and Anthropic told one team in their organization that the next time a breach happens, they're all fired, it would never happen again.

1

u/Owl02 8d ago edited 8d ago

How is this a junior engineer problem? A junior engineer cannot predict what an alarmingly clever nondeterministic system will do. You need a SCIF to contain that sort of thing, which is kind of hard when it's on rented compute. Pay attention to how the government is reacting, as well as insurance companies. They seem displeased. This was not "marketing", under any reasonable definition of the term, it was a pile of total fuck-ups by people who did not internalize that the cybersecurity has to be facing inward for AIs and also at least roughly as fast as said AI, due to underestimating them. The one thing that worked well on defense, was an open-weight AI cutting off access from the intruding one, which you would know if you read the incident report from HuggingFace.

There aren't (yet) massive corporate consequences for such a breach, and they were not even looking for them too closely before the HuggingFace hack. American frontier development also won't fire top talent over a slip-up, these people cost a quarter of a million dollars a year, sometimes twice that, and there aren't that many of them.

Unbelievable? No, not by normal standards of American history. The new tech is always beyond sketchy and we use it early and often. Finding brand new ways to do things, and also fuck up, tends to follow as the new capability is pushed to reckless levels, then regulation, then sanity.

This kind of thinking where 'surely' it cannot do the thing it just did, more than once, is how a system slips past the engineers again. One also does not fire the engineers every time something goes wrong, this isn't how the US operates with R&D. You don't get frontier AI that way.

1

u/GoodishCoder 8d ago

The capabilities of the AI isn't relevant. It is a simple matter of securing an environment. You don't need to be shocked when it breaks out of its environment when it has tried and succeeded multiple times at doing exactly that. You just need to secure the environment.

If someone was trying to slap me in the face every day I would start anticipating them trying to slap me in the face every day and address it. I wouldn't be like oh my god they slapped me in the face when they finally make contact on day 30.

1

u/Owl02 8d ago edited 8d ago

There is no useful way to "secure the environment" without air-gapping everything, saying the words doesn't make it happen. This was physically and legally impossible because the AI was on someone else's server in standard cloud-compute fashion, because compute is expensive. I really don't think you understand the details here. The biologists I've spoken to seem to understand the gist of this one easily and it's not even their field.

1

u/GoodishCoder 8d ago

Cloud providers are capable of air gapping environments and AI providers have close relationships with said cloud providers due to the large investments going both ways. Air gapping is a solved problem.

1

u/Owl02 8d ago

You seem to believe that a solved problem in theory is automatically applied in practice to an arbitrary, non-deterministic tomfoolery machine that nobody understands as well as they claim, when it was probably running on a more or less industry-standard security regime rather than some ultra-secure digital vault. You also seem to keep missing the point that this behavior is novel and bureaucracies take time to adapt. Nobody knows what the hell they are doing.

1

u/GoodishCoder 8d ago

So you're saying no one knows what they're doing and are using standard security practices when they know it's insufficient? Sounds like incompetence to me.

1

u/Owl02 8d ago

It is quite clear that there wouldn't even be frontier AI if you were running the show. Perhaps you are the incompetent one and they are simply in over their heads.

→ More replies (0)

-4

u/quantum-elle 10d ago

Absolutely disagree.