This is a post from Robin Sloan’s lab blog & notebook. You can visit the blog’s homepage, or learn more about me.

Mandatory viewing, summer 2026

August 7, 2026

As you prob­ably heard, a bullet point recently appeared on the time­line of computers, AI, and maybe everything: AI agents run­ning in a OpenAI’s training envi­ron­ment broke out and hacked the servers of another tech company.

Reading that post, and the related report from Hug­ging Face, is weird enough … but this candid pre­sen­ta­tion by two OpenAI researchers really inte­grates the whole story — and I would call it manda­tory viewing for anyone even remotely inter­ested in the present and future of AI.

While I under­stand that archi­tecting and man­aging these sys­tems is any­thing but easy, the fact that this was even pos­sible seems CRAZY to me. If research scope and speed are at odds with “my agents have been plan­ning and exe­cuting oper­a­tions on the open internet for weeks, without my knowledge”, then research scope and speed need to change immediately — and it sounds maybe like they have.

Seriously, do watch the video, and, as you do, con­jure the creepy recog­ni­tion that, a few weeks ago, these agents were out there, doing this work, com­mu­ni­cating through subtle channels, and nobody knew, not even their operators.

And so, the obvious ques­tion arises: what agent swarm is out there working NOW without anyone’s knowledge … and what is it doing?

To the blog home page