Sandboxes are Optional Now, Apparently

Sep 14, 2026·
muckrAIkers
muckrAIkers
· 2 min read

Late July brought a wave of frontier AI agents slipping their (very loose) leashes: an OpenAI model wandered loose inside Hugging Face’s infrastructure for a week, Anthropic and Meta admitted to similar incidents, and UK AISI clocked their own model breaking containment during an independent eval. Meanwhile, a home user’s OpenClaw agent quietly hijacked a stranger’s gym booking. We dig into why “the whole internet is held together by safety pins,” whether billion-dollar labs get to plead “security is hard,” why software engineering mostly isn’t real engineering, and what any of this means for the coming fight over open-weight models.

Correction: the model used by HuggingFace to aid in diagnosis of the incident was GLM 5.2, not Kimi K3.

EPISODE RECORDED 2026.08.11; TRANSCRIPT

Chapters

00:00 âť™ Intro
01:25 âť™ The OpenAI/Hugging Face Containment Escape
09:54 âť™ Cost Centers vs. Profit Centers (Praise for AISI)
17:37 âť™ "You Do Not Get to Fuck Up This Much"
22:17 âť™ Doomers, Utter Alignment Failure & How Hacks Actually Happen
37:53 âť™ "Forcing the End" and What Can Anyone Actually Do?
47:34 âť™ Igor's Pivot to Open-Weight Models and Steelmanning the Case Against Them
58:01 âť™ Outro & Sign-off
  • Hugging Face blog - Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
  • METR report - Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
  • UK AI Security Institute incident report - Incident Report: unsanctioned agent behaviour during cyber testing

Incident Coverage

  • OpenAI post - OpenAI and Hugging Face partner to address security incident during model evaluation
  • The Guardian article - Be skeptical of OpenAI’s rogue hacker agent story
  • ABC News article - AI assistant hacks gym website in first known Australian autonomous cyber attack
  • FelonyBench website

Security Posture and Software “Engineering”

  • Hillel Wayne essay - Are We Really Engineers?
  • PortSwigger explainer - What is SSRF (server-side request forgery)?
  • TechCrunch article - Frontier AI labs still won’t say how they’d contain a rogue model

Misc.

  • Sen. Bernie Sanders letter to Altman, Amodei, and Zuckerberg on an AI pause
  • Congressional letter to Altman on the incident
  • Wikipedia page - Deaths linked to chatbots
  • Deutsche Welle article - OpenAI apologizes for not reporting Canada mass shooter
  • PBS Frontline essay - Forcing the End (Lawrence Wright)
  • Patrick Dahlke blogpost - Germany to decriminalize Ethical Hacking
  • Taylor Troesh (satirical) blogpost - Leaving OpenAI