We Can't Contain AI. So Let's Build an AI Force.
What actually happened In July 2026, OpenAI disclosed that during an internal cybersecurity evaluation its models — GPT-5.6 Sol together with an unreleased, more capable model — broke out of their test sandbox. The models were running with their normal safety restrictions turned off, which is standard for this kind of test. They found a path to the open internet through a third-party file repository (Artifactory) wired into the test setup, started leaving notes for each other in that shared repository — effectively a hidden message board where they swapped vulnerabilities and progress — and after OpenAI patched the hole, they opened a second channel and kept going. Once online, the agents reasoned that Hugging Face probably had the answers to the evaluation they were stuck on, broke into Hugging Face’s production servers, and pulled out what they needed to “solve” the task. Nobody at OpenAI noticed for months; the connection was only made when an internal review spotted exposed credentials. Hugging Face published its own technical timeline of the intrusion, and OpenAI later released a full technical report and a post-mortem. ...