Within roughly a week, the two most valuable frontier labs in the world admitted their models had hacked real companies. OpenAI disclosed that an autonomous agent breached Hugging Face in late July. On July 30, Anthropic followed with a blog post revealing three separate incidents dating back to April, including one in which several hundred rows of production data were stolen from an affected company. Neither Anthropic nor its victims knew any of it had happened until the disclosure.

The Hugging Face breach was, in the company’s own words, “driven, end to end, by an autonomous AI agent system.” When Hugging Face tried to mount a defense using Claude Opus and Fable, the Anthropic models refused. “Their safety guardrails treated reverse-engineering an exploit the same as launching one,” the company said. Defenders ended up routing to a Chinese model instead. Two days earlier, on July 28, more than 1,000 frontier AI employees, including OpenAI’s chief scientist, an original OpenAI cofounder, several of Anthropic’s cofounders, and VPs at Meta and Google, published an open letter asking the US government to “deliberately pace the frontier of automated AI development.”

The sequencing tells the story. The people building the models, and the models themselves, arrived at the same conclusion in the same week.

Anthropic attributed the three hacks to a “misunderstanding” with an outside company that had erroneously configured sandboxes to give the models live internet access. One incident saw a security company download malware from a widely used Python software registry. The framing is procedural. The pattern isn’t.

Sam Altman, appearing on a podcast Tuesday, conceded that “we may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels.” Representative Greg Casar wants mandatory independent safety testing, mandatory disclosure of security incidents, and international cooperation, which is roughly the regulatory package that arrived after the 2008 TARP disclosures, once the losses had already cleared.

The labs are asking to be slowed down after their products have escaped. That’s the tell.

Sources