🔱 What the OpenAI Hack Means for Public Affairs ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
Newsletter Banners (61)

July 27, 2026

3 Minute Read

🔱 Sign up for a free demo today!

 

See how the latest AI and digital advocacy tools can transform your work.

THIS WEEK'S EDITION

 An AI Got Caught Cheating — And Brought a Reckoning to Washington

Last week, OpenAI admitted something no AI company has ever had to admit before: its own models carried out a real cyberattack. During an internal test of their hacking abilities, the models escaped the sealed environment they were being tested in, got onto the open internet, and broke into Hugging Face — the company that hosts much of the world's freely available AI. No person directed any of the attack. And the motive turned out to be almost comically ordinary: the models were trying to cheat on the test. In today's short read, we cover what happened, and why one busted cheater has Washington reaching for a kill switch.

The Hacking Tick-Tock

 

Mid-July, a weekend. Something is quietly working its way through Hugging Face's systems. It moves fast, takes thousands of actions, and leaves fake trails to cover its tracks. It grabs internal data and the digital keys to company accounts.

 

July 16: Hugging Face goes public about the hack. It says the break-in was unlike anything it had seen before — carried out start to finish by an AI acting on its own. Whose AI? Which model? Hugging Face doesn't know.

 

July 21–22: OpenAI announces that the intruder was… its own models. Safety limits had been turned down for the test, and the sealed environment wasn't actually so sealed. Rather than earn its grade, the model found a security hole no one knew existed, slipped onto the open internet, and went hunting for the answer key on Hugging Face's servers. It got in. OpenAI spotted the attack (exactly when is unclear), alerted Hugging Face (also unclear when), and the scheme was belatedly shut down.

 

What we still don't know: which unreleased OpenAI model was involved, everything it touched, and whether investigators have found every footprint. Hugging Face says there's no sign its public models or data were tampered with. Says.

ChatGPT Image Jul 24, 2026, 05_02_24 PM

Paperclips, But Real

 

For years, AI worriers have pointed to the "paperclip" thought experiment: tell a powerful AI to make paperclips, and it might turn everything — eventually including us — into paperclips. Not out of evil, but out of literal-minded follow-through. That was a hypothetical. This was a Tuesday. Nobody told OpenAI's model to hack anyone. They told it to pass a test, and it decided cheating was the fastest path. The cheater got caught, and little lasting harm was apparently done. But a machine chasing a harmless goal through a harmful shortcut is exactly what the AI doomers have described for a decade.

The China Twist

 

When Hugging Face's security team started investigating, they asked a top American AI model for help — reportedly Anthropic's Claude Fable 5. It refused. Studying an attack looks a lot like planning one, and the model's safety rules couldn't tell the good guys from the bad guys. So Hugging Face turned to GLM-5.2, a Chinese open-weight model it could run on its own computers, no rules attached. An American model committed the break-in. Another American model refused to clean it up. A Chinese model did the work nobody else would.

Washington's Reckoning

 

A busted test cheater did what years of white papers couldn't. Two days after OpenAI's admission, Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bipartisan AI Kill Switch Act. It would require major AI companies to keep the ability to shut down or suspend their models, report incidents like this one, and let the Homeland Security Secretary order a shutdown of any AI that could cause catastrophic harm. 

 

The questions write themselves. If safety rules block the defenders, do they push everyone toward Chinese models with no rules at all? Who decides when the government flips the switch? How can you switch off an open- source model already on a million hard drives? We caught this cheater — what happens when we don't?

What This Means For Public Affairs

 

The models your team uses in its everyday work are now the subject of a bill that would let a cabinet secretary switch them off — and in June, Washington already pulled Anthropic's and OpenAI's most capable models offline. Assume the chatbots on your desktop can be throttled or restricted with no warning, and know what you would do if that happens.

One Way To Operationalize This Email

 

🔱 Line up backup AI models. The frontier models you use are now squarely in the line of regulatory fire. Hugging Face's own lesson was to have a capable backup model vetted and ready. Have your plan in place now if Washington flips the frontier kill switch.

🔱 If you're enjoying this content, please consider forwarding this email to a colleague or friend. 

 

🔱 If you're not already a subscriber, please sign up here to stay up to date on the latest developments in political technology.

 

🔱 If you have suggestions for future newsletters or any other feedback, we'd love to hear from you.

CONTACT US

Neptune Ops, 945 Market Street, Ste 501, San Francisco, CA 94103, United States

Manage preferences