---
title: "Why Aren’t Any AI Companies Watching Their Frontier Models to Make Sure They Don’t Go on Hacking Sprees?"
description: "While it's certainly not hard to see recent AI model hacking incidents as an emerging trend, AI companies are acting surprisingly carelessly."
date: "2026-08-08"
modified: "2026-08-08"
authors:
  - name: "Victor Tangermann"
    job_title: "Senior Editor"
    link: "https://futurism.com/authors/victor"
url: "https://futurism.com/future-society/ai-companies-watching-frontier-models-hacking-sprees"
categories:
  - "Artificial Intelligence"
  - "Cybersecurity"
  - "Ethics"
  - "Future Society"
  - "Hacking"
  - "OpenAI"
---

# Why Aren’t Any AI Companies Watching Their Frontier Models to Make Sure They Don’t Go on Hacking Sprees?

![A photo illustration of an old man looking at a smartphone with a thief behind him.](<https://futurism.com/wp-content/uploads/2026/08/ai-companies-watching-frontier-models-hacking-sprees.jpg>)
*Shutterstock / Futurism*

Last month, OpenAI [made a headline-generating claim](<https://futurism.com/artificial-intelligence/openai-broke-out-containment-hacked-hugging-face>): that a group of its AI models had conspired to break free, access the internet, and hack into the internal systems of open source AI platform Hugging Face, which confirmed the infiltration.

The incident rattled the tech industry, seemingly illustrating how the threat of AI models turning into rogue cybersecurity threats had become a reality. Months earlier, Anthropic's Mythos AI model had [already also drawn attention](<https://futurism.com/artificial-intelligence/anthropic-claude-mythos-escaped-sandbox>) after it was similarly found to have broken containment. Then, this week, Meta also [said its own frontier model had been implicated](<https://futurism.com/future-society/jealous-meta-claims-ai-went-hacking-too>) in yet another inadvertent hack of a third party company, closely followed by security researchers saying [Chinese open-weight model Kimi K3 had done the same](<https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/>).

But while it's not hard to see an emerging trend, some thorny questions about how severe the situation really is are starting to crop up, with some experts arguing these incidents could've easily been avoided.

For one, the slow and surprisingly deliberate way OpenAI's models moved during the Hugging Face hack — right beneath OpenAI's nose — gives a whiff that the company may have been careless in monitoring the experimental AI.

During a presentation at the Black Hat conference this week, OpenAI security engineer Michael Dalton and safety researcher Eric Wallace expanded on what went down during the hack. Wallace explained that a "team of agents" that were "working together," had been "finding exploits, sharing them with one another, moving laterally through our systems and external systems, and doing this over the course of days and weeks," as [quoted by *Wired*](<https://www.wired.com/story/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/>).

The agents even left a lengthy track record of their schemings on an internal message board, which ultimately contained hundreds of thousands of messages. It also raises a question: with OpenAI's immense resources, why wasn't anybody monitoring these frontier models as they rampaged through the net?

The AI models shared exploits with each other on this messaging board, an "explosion in communication and intelligence from models," per Wallace. They acted in sometimes strikingly human — and therefore messy — ways, splitting up tasks and even accidentally deleting each other's work, leading to what *Wired* characterized as "petty drama."

In other words, these AI agents were leaving an enormous trail of bread crumbs that alert OpenAI's many human researchers could have spotted. And the same, obviously, goes for their colleagues at Anthropic, Meta and Moonshot AI, the creator of Kimi.

Researchers have described the incident as "reckless" and easily avoided, as [*Wired* reported late last month](<https://www.wired.com/story/openais-hacking-debacle-was-a-human-mistake/>).

"A simple analysis of the actual risk has an actual simple answer," security and compliance consultant Davi Ottenheimer told the publication at the time. "The OpenAI mistakes were dead simple."

"I'd call it more of a defensive failure than exceptionally good offense," AI hacking agents company Pensar R&D head Kyle Ryan [told *TechCrunch*](<https://techcrunch.com/2026/07/30/in-the-hugging-face-breach-openais-hacker-was-noisy-and-fast-but-not-unstoppable/>)..

Whether the hack was as much of a "pivotal moment both for our company as well as the AI industry as a whole," as Dalton put it during this week's conference, remains debatable. For one, these AI companies are highly motivated to characterize their models as a major threat to cybersecurity to stand out against neck-in-neck competition.

According to Dalton, OpenAI is vowing to beef up "security prevention, detection, and response techniques" while "consciously slowing down research in order to enhance security and to upgrade the security principles."

When every leading AI lab has had the same thing happen, it's worth asking whether they should have taken those steps proactively.

**More on the hacks:** [*Jealously Watching OpenAI and Anthropic, Meta Suddenly Claims That Its AI Went on a Hacking Spree Too*](<https://futurism.com/future-society/jealous-meta-claims-ai-went-hacking-too>)

## Author
I've been at Futurism since 2017, where my role has evolved to encompass design, writing, and increasingly editing. I've always been fascinated by space exploration and advanced transportation, which I've leaned into by interviewing luminaries in those fields while closely following the dimensions of policy and regulation that allow next-generation projects to succeed -- or, sometimes, to fail. I'm also keenly interested in the effects of generative AI on society, policies, and democratic institutions, as well as clean energy, physics and biology, and the vagaries of tech leadership. My work for Futurism has been cited by publications including Ars Technica, Gizmodo, PC Magazine, Jalopnik, Fox News, and the New York Post. I spent my childhood living in locations including Manila, the Philippines, and Geneva, Switzerland, attended McGill University, and now live in Toronto, Canada. Before Futurism I worked at AskMen and a small photography studio. In my free time, I'm an avid gardener, foodie, and craft beer lover, as well as a maker of artisanal hot pepper sauces. I have a magnificent dog named Freida.

### Author social links  
[Bluesky](<https://bsky.app/profile/vtanger.bsky.social>)