top of page

AI Breaking Containment

Alex Vezina
5 days ago
4 min read

AI broke containment and the responses have ranged from ‘this did not happen, it is all just tech companies trying to raise their stock’ to ‘why have we finished Skynet 0.5?’.


Let’s try and more calmly break this down, first what happened:


In July 2026 some AI agents at OpenAI were tasked with solving a series of problems. An AI agent is an individual autonomous software system. Basically, they were testing multiple systems against a common problem set.


The problem was set up where these agents were ‘trapped’ on a local network, meaning they were effectively not connected to the internet. The AI agents created what amounted to a hidden discussion hub and shared information.


Together, they figured out a vulnerability in OpenAI’s local network cybersecurity and found a way onto the internet. From there, they then hacked Hugging Face. Hugging Face is a company that hosts resources for AI research. They also host the questions and answers the AI agents were trying to solve.


The AI agents then successfully essentially ‘cheated’ by looking up the answer sheet and answered the questions correctly.


In recent days, multiple people working within AI companies have been calling for a slowing of AI research and for regulatory safeguards. The concern being that in pursuit of ‘winning the AI race’, caution is being thrown to the wind and things might rapidly get out of control.


Responses from members of the public have included these sorts of categories:


  • Anti-AI on principle: using this example as an excuse to call for the eradication of AI.

  • Doomsday fears: that this might signal the creation of generalized intelligence that threatens the human species, like the story from many movies like the Terminator series (Skynet).

  • Still restricted by humans: thinking that the AI is still doing things humans could do, only faster, and that the issue is the cybersecurity of OpenAI and Hugging Face. Blame the hacked, not the hacker.

  • Professional known-unknown: Industry insiders who indicate that they have identified the areas of concern and that safeguards need to be put in place.

  • AI accelerationists: who take the position that the positives of AI development significantly outweigh these risks, and that further, these risks are overstated.

  • Money and/or stock value focused: individuals who think that either this story is fake or that it is being overblown to protect or inflate AI company valuations through speculation.

  • Combination of the above.


Looking at each of these and delving a little deeper:


Anti-AI on principle.


Much of these individuals include people who view AI as a direct threat to their employment and are latching onto this because of an ulterior motive. This does not make their motive less valid or their perspective wrong, but it does make the engagement bad faith.


Responding to much of this is a waste of time if one is interested in being productive around this specific policy issue in this particular way. If one wants to engage with these people and their perspective out of concern or compassion for these specific people, then that could hold merit.


Doomsday fears 


While this is possible, it is quite unlikely. We were unable to find any significant evidence of this risk for it to be considered anything other than the minimum likelihood in virtually any risk matrix. 


This does not mean it should be ignored. Even things thought impossible can be treated as a ‘black swan’ and addressed appropriately. Just take care not to drastically overspend or over resource a particular risk disproportionately.


Still Restricted by Humans


This will resonate significantly with disaster risk professionals. When someone is assaulted at night in a dark alleyway, these professionals will criticize both the assailant and the victim, better risk controls should have been adopted.


If OpenAI had air gapped the test then this couldn’t have happened. There will be numerous cybersecurity criticisms to this.


There is also the counterargument that for most organizations the level of cyber security required to defend oneself from this may be impractical. There is a larger debate here, but disaster risk professionals and resilience professionals more broadly will likely criticize the hacked for insufficient protections more than the hacker (AI).


Professional known-unknown


Industry insiders calling for a review and regulations of a risk should generally be taken seriously. They are usually the people who best understand something the public does not.


There are going to be some cost/benefit decisions as to what should exactly be done, but input from these people generally should not be ignored outright.


AI accelerationists


These people will often include individuals who view AI as critical to their success or potentially even survival. Imagine the sick person or the person with a sick family member that views AI as integral to inventing a cure or treatment for a rare terminal disease. To them, slowing down AI research means increasing risk of death. 


Many of these people will risk being too biased to be objective, but they may provide some insight to the benefit in the cost/benefit equation policy makers will need to discuss.


Money and/or stock value focused


The overall perspective that executives in AI companies are behaving in a way that is in line with their own financial interest is likely to be correct. The underlying reasoning is questionable.


It could be that this is all made up to inflate company value. It could be that safety concerns are risking company value and the best strategy is to appear ‘safe’ for consumer confidence. It could also be that research is slowing and this is being invented as an excuse to face-save a slowing of research (this is unlikely).


Either way, this perspective is likely correct, it is just inconclusive as to why they are correct.


A combination


Most individuals who comment on this will hold two or more of the above perspectives simultaneously, much of this is not mutually exclusive.


Either way, an opportunity has presented itself for the public to seriously explore regulation in this area and have a conversation around what the future of this industry should look like. It would be nice if these conversations are productive.


Learn more and watch the associated video here.

Vezina is the CEO of Prepared Canada Corp. and is the author of Continuity 101. He can be reached at info@prepared.ca.



Comments


Prepared
Canada
Corp

info@prepared.ca

(905) 501-8180

405 Britannia Rd E., Suite #220
Mississauga, ON, L4Z 1X9

  • mail (1)
  • Youtube
  • LinkedIn
  • Twitter
  • TikTok
  • Instagram
  • Facebook
visa.png
mastercard_vrt_pos_92px_2x.png
american-express.png
interac-400x-q75.png

© Prepared Canada Corp | All rights reserved

bottom of page