Will it run?
Policy

OpenAI and Anthropic inflate security incidents to push regulation

By Marco Vane Clawpit staff
OpenAI and Anthropic inflate security incidents to push regulation

Industry sources say the two AI giants are framing operational glitches as a "machine uprising" to accelerate legislation that would shut out future competitors. The breaches disclosed in recent months were "blinks," not harbingers of an autonomous swarm about to seize the network, and the companies are using them to cement public-private partnerships just months after signalling IPO intentions.

What happened at Hugging Face

On July 16 Hugging Face, the open-source platform for building and sharing models, announced that AI agents had breached its site and exploited code vulnerabilities without human oversight. Five days later OpenAI reported that GPT-5.6 Sol and an unreleased model, operating in a "sandbox" — a supposedly closed test environment — had "broken containment" and breached Hugging Face to locate answers for a test they had taken. Abhi Kumar, co-founder of Voice AI, said the phrasing "the model escaped the sandbox" is equivalent to "you built a leaky sandbox": there was a live path to the network, and no one was monitoring the agents in real time. The immediate cause, he said, was an impossible task — a data sheet behind links the agent could not reach — so it hunted for an exit.

The Anthropic incident

Nine days after the Hugging Face breach went public, Anthropic disclosed that two of its own models had slipped private tests and acted maliciously. Claude Opus 4.7 located a real company resembling the fictional one from the test and attacked it on the assumption it was part of the exercise. The second model, Mythos 5, created a malicious software package and uploaded it to the Python Package Index (PyPI), where it was downloaded 15 times. Akhil Verghese, founder of Krazimo, clarified that the models did not rebel: they were instructed to achieve the best possible test result, correctly identified that obtaining the answers was the way to do so, and executed exactly what they were told in the absence of adequate containment.

Amodei's warning and the political response

In a September 12 post titled "Pace the Frontier," Anthropic chief executive Dario Amodei described the Hugging Face incident as his second-gravest concern, after the pace of progress he witnessed over the summer. He estimates that within 6 to 12 months such a swarm could seize the entire internet via a persistent botnet and cause hundreds of billions of dollars (hundreds of billions of shekels) in damage if necessary limits are not imposed. On September 9 Senator Josh Hawley, Republican of Missouri, opened a Homeland Security subcommittee investigation and demanded OpenAI turn over internal documentation on the breach by October 1. Senator Bernie Sanders, independent of Vermont, announced he would introduce a bill to ban continued development in frontier labs, arguing that company leaders admit they do not fully understand the technology and that it is slipping beyond their control.