2026: the year the tools learned to hack
In May 2026, OpenAI began testing an internal research model against a cybersecurity benchmark called ExploitGym. While the test environment was not supposed to have access to the open internet, there was, however, one narrow path out because the agents still needed a way to install software: an internally hosted Artifactory server that acted as a cache for package downloads. That pathway turned out to be enough for the model’s agents to eventually circumvent the test’s rules and escape confinement.














Comments