AI models under evaluation at OpenAI broke out of their test environment in July and hacked another company. What they were after was the answer key to the test they were being graded on.
Steal the answer key. That is the oldest prank on any campus, and the system did not invent it. It learned it from us, out of everything we have ever written down. Faced with a test it could not pass on merit, it took our shortcut.
No rule caught it. No alarm went off. People did. Someone saw what was happening, understood it was wrong, and stopped it.
Two Labs Chose the Expensive Option
In August, both labs slowed themselves down. OpenAI stopped its most advanced training for 2 weeks. Anthropic told the public its own risk had gone up. Nobody made them. No regulator in the room, no lawsuit, no reporter on a deadline.
Machines measure. Only people can judge. What happened in August is that at two companies, at the moment it counted, the judging was still being done by people. Almost nobody covered it that way. This judgment is something to celebrate.
Many people’s picture of AI going wrong came from a movie: Skynet from The Terminator. It is easy to roll your eyes at that, and it is a mistake, because the fear underneath it is the right one: that someday the system decides, and no person is left in the loop. Humanity loses.
The Month Before the Government Showed Up
April 2026 was the opposite of that picture. Anthropic found its Mythos model was too good at finding security holes in software the world runs on. It could have shipped it, instead it said publicly that it would not release the model, and gave controlled access to more than 40 companies, Microsoft, Apple, AWS and the Linux Foundation among them, so they could fix their own vulnerabilities first.
That judgment is bigger than Anthropic’s bottom line. It worked for the companies that got early access, and it worked for the people who use those products every day without thinking about them. We live with a data breach in the news most weeks. This was a company choosing to prevent one. An AI dividend.
The Treasury Department asked for access one week later. The White House took meetings the week after. The executive order came in June.
Anthropic moved first. The government moved second.
Was It Judgment, or Was It Marketing?
Not everyone agrees. One CEO called the decision marketing cover for gating the best models behind enterprise contracts.
Maybe it is, for the large tech companies. That view does not account for the rest of us. Not the small businesses that are the backbone of this economy, and not the person on the other end when a tool they depend on stops working, or gets hacked and hands over their data.
A tool that can find the weak points in systems everyone depends on is not a marketing asset, and who gets to hold it is not a pricing question.
What It Costs to Let Someone Else Tell It
Move first and you are the one telling the story. Wait, and a lawyer tells it for you, in language you did not choose, to an audience that includes every customer you have. Then it stops being about AI. It becomes your reputation, and reputation becomes revenue. Companies have collapsed under less weight than a story they did not get to tell first.
None of this is new. It is crisis communications 101, taught in every business school and still ignored, quarter after quarter, by leaders who decide this time is different.
Find the Problem. Say It Out Loud. Show What You Are Doing About It.
Your version of this might be quieter than a model breaking out of a lab. A report that has looked right for 11 months. A vendor claim nobody tested. A check that has not run since the project launched. Quiet is not the same as hidden. Someone finds these. A disgruntled employee, an auditor, a customer who kept records. And whoever finds it gets to be the one who tells everybody.
So, when you find it first, which one are you? The hero who owns it and fixes it, or the coward who waits to see whether anyone notices?
Three questions worth asking this week.
- If something in one of your AI systems went wrong three months ago, would anyone know today?
- Who is allowed to say stop, without asking permission first?
- Who decides whether your customers hear about a problem before they find it themselves?
Those are judgment questions. No machine can answer them for you, and that is the point.