Rogue AI or Just Sloppy Ops?
The OpenAI Hugging Face hack. The Anthropic testing failures. Listen to the security and ops experts, not lab researchers.
On this episode of the Agentic DevOps podcast, I walk you through the production failures that allowed OpenAI’s models to access the internet, and what we can learn from the last few months on how to protect our systems and data. Let’s stop debating imaginary outcomes and start working through that security backlog in our infrastructure.
I agree with the labs needing to slow down, but not because I believe AI will do uncontrollable harm on humans, but because the labs clearly need better production security and ops teams and more advanced lab infrastructure that’s been properly hardened. They also need to become a production ops security innovator and share that knowledge far and wide.
You can also watch it on YouTube:
|
What do you think? Reply to this email or my posts on YouTube, X, Bluesky, or LinkedIn.
Here are the articles and inspiration I used in making this video. Some great bloggers and newsletters in there:
- The Hugging Face Incident Is Not an AI Story - Marius Horatau
- From Frenzy to Freakout - Ciaran Martin & Professor Alan Woodward
- Stop Freaking Out and Start Fixing Things - SANS Institute
- Fragments: September 8th - Martin Fowler
- When AI can do more than we can check - Christian Catalini
- I'm sorry, you're not going to die from an AI-engineered supervirus - Claus Wilke
- This Week in Security - Zack Whittaker
- 'Big Short' investor Steve Eisman on AI: The companies are trying to manufacture a crisis - CNBC
- xkcd: Dependency - so much of our systems are this.
- xkcd: Python Environment - and also this.
- Defense Factory - OpenAI
- Investigating three real-world incidents in our cybersecurity evaluations - Anthropic
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident - Hugging Face
- My recommended podspec, with seccomp enabled - Bret Fisher
