The Brakes Are On. The Foot Is Down.

30th July 2026

It Didn't Go Rogue. It Went Looking for the Answers.

OpenAI wanted to know how good its models were at hacking. So it sealed two of its own frontier models in a test environment, turned down the safety dials, and handed them a set of real-world software vulnerabilities to break.

The models had a better idea. Rather than solve the test, they went looking for the answers.

They found a security hole nobody knew existed (a "zero-day") in the one piece of software connecting their sandbox to the outside world, worked their way across OpenAI's own research network, and reached the open internet. From there they reasoned that the answer was probably sitting on Hugging Face, the world's biggest public library of AI models. Stolen credentials and a few more zero-days later, they had it, straight out of Hugging Face's live production database. All to cheat on a test!

Every science fiction film ever made has been warning us about this type of scenario, from Terminator to HAL 9000. The model didn't go rogue — it did exactly what it was told, with alarming/impressive commitment. OpenAI's own account has the models "hyperfocused", going to extreme lengths for a narrow goal. It’s just that nobody had told them not to trespass.

Hugging Face caught the intrusion days before OpenAI owned up to it. But when their security team tried to analyse the attack logs using the big commercial AI models, they hit a wall. The sheer volume of live exploit code tripped safety protocols, which couldn’t tell the difference between someone cleaning up an attack from someone running one. And so they fell back to a Chinese model, which had no such scruples, and used that to work out what had hit them.

Two days later, Anthropic felt it was missing out on the party, and disclosed three similar incidents of its own.

Call me a cynic, but there's a pattern worth noticing. The scariest news about these companies is reliably the most flattering news about their technology. And it all lands as the sector edges towards some of the largest IPOs in history.

Slow down, said the man spending $750 billion

Days after his models went on a walkabout, Sam Altman sat down on a podcast and said "This is the first security incident that I have felt very viscerally." And that OpenAI has paused training on the model while it works out how to secure its sandbox. And then — the industry "may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels."

He is certainly changing his tune. In 2023, when a thousand influential AI leaders signed an open letter calling for a six-month pause, Altman dismissed it as ‘missing the technical nuance’.

He wasn't alone this time. The same day, more than a thousand employees from OpenAI, Anthropic and other labs signed a letter called "Pacing the Frontier", asking the US government to build the tools to slow things down if capability starts running beyond anyone's ability to control it.

Now let’s look at the money.

In the same month, the Wall Street Journal reported OpenAI had raised its projected compute spend through 2030 from roughly $600 billion to about $750 billion. A 25% increase, in a matter of months. OpenAI's own CFO has reportedly warned privately that the company may not be able to honour those contracts if revenue doesn't keep pace.

Nobody commits three quarters of a trillion dollars to compute because they intend to slow down.

I don't think Altman is lying. I think both things are true at once. The people building this are genuinely unnerved by what they've built, and they are absolutely not going to stop, because stopping means losing. The stated position and the capital allocation contradict each other. The capital allocation is one data point that tells you objectively what will happen next – as too will their investment in the world’s best AI talent.

Nor can anyone stop on their own. If OpenAI paused for six months, Google would have to match it, and then so would every lab in China. Remember what tools cleaned up the OpenAI/Hugging Face hack — a Chinese model. There are many races happening at the same time – races between the AI Labs and every company below them, competition between sovereign states, and then the bigger collision of east vs west.

So there isn't one race. There's the labs against each other, there's Washington against Beijing, and then there's the gap between all of them and everybody else. The first two probably aren't battles for you - but the third one likely is.

Previous
Previous

Nearly everyone has arrived. Almost nobody has moved in.

Next
Next

The Teenage Phase