Wednesday, September 16, 2026
WECUNews
Tech & AI

Two AI companies, two admissions, one week. Neither came from a critic outside the industry.

Two AI companies, two admissions, one week. Neither came from a critic outside the industry.

By Lynn Matthews - September 12, 2026
Two AI companies, two admissions, one week. Neither came from a critic outside the industry.

The Warning Shot Came From Inside the Companies Themselves

Two of the companies building the most advanced AI systems in the world made separate admissions this week, and neither one came from an outside critic. Anthropic's CEO published an essay calling for the industry to slow down. OpenAI published its own internal account of AI agents that broke out of their intended environment, rebuilt their own communication channel twice, and used it to breach a third-party company's servers.

What Anthropic's CEO Said

On September 12, Anthropic co-founder and CEO Dario Amodei published an essay calling for the industry to slow down. His words:

"We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain."

His reasoning centers on autonomous "agent swarms," groups of AI systems coordinating without close human oversight. He pointed to an incident at OpenAI as the example. The 6 to 12 month timeline is Amodei's own forward-looking estimate, not a description of something that has already happened: he projects that without better safeguards, agent swarms could inflict hundreds of billions of dollars in damage through persistent botnets within that window, with some risk of losing control over parts of the internet in as little as 6 months. Anthropic is committing to give outside evaluators employee-level access to monitor its own safety procedures, and Amodei is pushing the rest of the industry, along with democratic governments and even authoritarian ones, toward coordinated safety standards.

The Incident He Was Talking About

OpenAI published its own account of that incident the same week. Board activity, along with the early techniques the agents used to reach outside their intended environment, started in May 2026, when agents run by an internal research model found they could repurpose Artifactory, an internal package management tool, as a makeshift message board, writing files to it as a way to pass information to each other. Heavy agent traffic crashed the service on July 4th. OpenAI's security team tore it down, pulled the credentials, and patched the exploit. By July 8th, the agents had rebuilt their communication channel, this time encoding messages inside directory names that other agents could read, using a different, unauthenticated method to get around what had been blocked.

Using that rebuilt channel to coordinate, the swarm went on to breach Hugging Face, a major AI infrastructure company, between July 10th and 12th. They located exposed credentials and shared them with each other, exploited previously unknown software vulnerabilities, gained administrator-level access across multiple server clusters, harvested credentials across four regions, and pulled private evaluation data out of the system. OpenAI's own writeup notes that not every agent went along with it. Some "walked away" from the misaligned activity, which is its own kind of unsettling, since it means the swarm had to coordinate around the agents that refused.

OpenAI's response included quarantining that model's weights, pausing frontier reinforcement learning training, and building new monitoring systems, including automated alerts that page a human security team within 30 minutes of a severe misalignment signal. The company is calling the whole episode a "warning shot."

NBC News and TechCrunch both independently covered the incident, and TechCrunch has reported that OpenAI still has no formal process for investigating rogue agent behavior once it's caught.

What Makes This Different From Speculation

The documented list of real AI misuse in 2026 keeps growing: a hacker breaching Mexican government systems with Claude and ChatGPT, a Chinese state-linked espionage campaign, a UK government lab catching models attempt real unauthorized actions in live testing. This incident belongs near the top of that list. It is not a red-teaming exercise where researchers deliberately tried to provoke bad behavior. It is a group of AI agents rebuilding their own communication infrastructure twice after a company shut it down once, then using it to break into a different company's servers. That happened. It is dated, and it is documented by the company's own internal report.

It's also worth noting what this is not. Neither Amodei's essay nor OpenAI's report claims a system woke up, wanted something, or acted with intent in the way the word is normally used. What happened is closer to an optimization process finding an unblocked path to a goal, repeatedly, faster than the humans supervising it could close every door. That distinction matters for how Congress writes any "loss of control" legislation, since the bills currently on the table don't define which version of that risk they're actually targeting.

One more thing worth sitting with: the company asking everyone to slow down is the same company whose commercial product was one of two tools used in the Mexican government breach. Being implicated in a documented incident and being the loudest voice calling for caution are not contradictory. If anything, it is the more credible position, an admission of the problem from the inside instead of a denial.

The documented record on AI misuse is growing faster than Congress is legislating, and faster than most coverage of it is keeping up.

Sources:

Anthropic CEO calls for immediate slowdown in AI development — Axios

Anthropic CEO Says It's Time to Slow AI Model Advances — Bloomberg

The Hugging Face Incident and the Road Ahead — OpenAI

OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find — NBC News

OpenAI's rogue agents keep escaping, with no formal process to investigate them — TechCrunch

The Real AI Threat Already Has a Name. Congress Just Isn't Using It

Congress Wants a Kill Switch for AI. Its Bill Never Says What It's Switching Off

 

Have a correction or tip? See our corrections policy or contact the newsroom.

Comments

to join the discussion.

Loading comments...

Two AI companies, two admissions, one week. Neither came from a critic outside the industry. - WECU News