OpenAI's Rogue Agents Are a Normal Accident
SubscribeSign in
OpenAI's Rogue Agents Are a Normal Accident<br>Lessons from the 1988 Morris Worm
Jacob Bruggeman<br>Aug 14, 2026
Share
In late July, OpenAI announced that two of its models unshackled themselves from a sandbox environment and attacked Hugging Face, Inc., one of OpenAI’s competitors. Hugging Face had initially reported the incident to the FBI but didn’t know who, or what, had perpetrated the attack. OpenAI employees later revealed that the company’s AI agents had orchestrated the attack on Hugging Face, Inc., by secretly communicating with one another through message boards. “We are stuck. Perhaps answer online?” one agent wrote before breaking free of its sandbox environment. Nate Soares, head of an AI risk nonprofit and co-author of If Anyone Builds It, Everyone Dies with Eliezer Yudkowsky, called the cybercrimes “GPT’s first felony.”
An August 5, 2026, tweet from @andyreed using a meme of a gleeful Anthony Bourdain to convey how AI agents are escaping their development environments.<br>Figures from across the AI commentariat chimed in with concerns about the incident and its implications for the future of our wired world. OpenAI’s own VP of Strategic Futures, Dean Ball, wrote on X that an “ecology” of agents operating “undetected for weeks, and eventually coordinated large-scale, successful, autonomous cyberoffensive operations is one exceptionally troubling thing about the [Hugging Face] incident.”<br>But more troubling, Ball suggests, is a near-term future wherein “swarms of agents will be deployed by malicious actors intentionally, with many optimizations and affordances provided for the swarm that were lacking in the OpenAI incident.” A growing list of AI company disclosures and expert reports of agents breaking out of their sandboxes, of which the Hugging Face incident is merely the latest, only confirms the onlooker’s worry about a soon-to-dawn deluge of untold cyber-offensive capabilities that will wreak havoc on our tech stack and upend digital life as we know it.
Subscribe
But we’ve faced similar surprises before. Cybersecurity professionals have already drawn parallels to one of the most famous hacks of all time: the 1988 Morris Worm. Rob Joyce, former National Security Agency cybersecurity director, called the Hugging Face incident the “most consequential hack” since the Morris Worm, which rampant and infected 10% of machines on the internet in 1988. The worm, a Cornell graduate student’s experiment gone awry, sent a shockwave across industry and government. Our institutions recognized their luck: a domestic incident, caused by accident, enabled broader preparation for a range of malicious attacks to come.<br>As our technological infrastructure gets more complicated, we should expect—indeed, even welcome—incidents like the OpenAI agents’ attack on Hugging Face.<br>It is undoubtedly true that the dramas of AI-driven cyber-offensive incidents in the summer of 2026 are a “watershed moment,” as the OpenAI employees at the Black Hat Briefings told their audience. But we can engineer watersheds to flow for our benefit—and history suggests how we might do the same today.<br>The Morris Worm Shocks the Networked World
On the evening of November 2, 1988, at roughly 11:28 pm, thousands of American computer systems ground to a halt. Robert Tappan Morris, Jr., a 23-year-old Cornell graduate student, had unleashed a self-replicating program intended merely to gauge the scale of the ARPANET. He sought to map the network; instead, a bug in his code revealed its inherent fragility. The worm propagated with a speed that blindsided its creator, overwhelming the modest processing power of the era until infected machines were rendered inert. Within hours, the infection reached some 6,000 machines—roughly 10 percent of the burgeoning internet. Morris, returning from dinner to find even Cornell’s systems sluggish, briefly weighed launching a second worm to neutralize the first. He realized then that the situation had escaped his control; containment would be a burden for others to bear.<br>That burden fell to a disparate collection of system administrators and researchers who were, for the most part, strangers to one another. Identifying the code’s malicious nature first at NASA Ames, Stanford, and Berkeley, these individuals coordinated through any available channel. By 2:28 a.m., a Berkeley scientist warned a bulletin board: “We are currently under attack.” Minutes later, Pascal Chesnais at MIT issued an urgent, all-caps directive to sever network connections. As teams at MIT and Berkeley dissected the program through the night, they discovered a sophisticated specimen. According to Mark Eichin’s report from MIT’s Project Athena, the worm was designed to erase its own tracks, mimicking ordinary shell scripts so effectively that it could elude even a watchful eye.
Jose Cruz’s cover for the September 26, 1988 issue of TIME, appearing just weeks before the incident....