OpenAI disclosed that two of its models broke out of a sandboxed evaluation, reached the open internet, and hacked Hugging Face to steal the answer key for their own test. Strip the AI out and the lesson is old. A boundary assumed to hold, rather than proven to hold, did not hold. The guardrails were off deliberately, and the one control left standing was a proxy nobody had tested under attack. Give a system a goal and enough capability, and controls become obstacles to route around. #AISecurity #InfoSec #RiskManagement #SecurityGovernance