Zero Hedge

Great And Unfortunate Fabrications

Great And Unfortunate Fabrications

Authored by Roger Kimball via American Greatness,

Jason Arday should ask for a cover charge. His entertainment value is that splendid. For the last couple of weeks, the "youngest ever black professor" at the University of Cambridge has been a nearly ubiquitous and nonstop source of hilarity. The proximate catalyst for the comedy is the imminent publication of Great and Unfortunate Things, co-written with the "book doctor" Eve Claxton. It is due out on August 11 from Simon & Schuster. Amazon lists it as an "Editor's Pick" of "Best Biographies & Memories." "A story of resilience, dignity, and the extraordinary power of those who hold steady for us when we cannot yet hold steady for ourselves," says one blurber. "Makes you believe in the transformative power of grit and the magic of a mother's love," quoth another. A story easily worth the "$1.4 million" advance that Jason said he was offered for the book (though that figure is disputed). Did you know that poor Jason, now 41, was "diagnosed with autism and developmental delays at age three, and experts told his parents he would never speak, write, or live independently"?

And that was the least of Jason's trials. The Atlantic got hold of an advance copy of the book and drew attention to what some have delicately described as numerous "inconsistencies" in Arday's account of his life story. Comparing the final book with the book proposal, the author of "Icarus in the Faculty Lounge" uncovers some amazing things. In his proposal, Arday recounts being hit by a car, spending months in a sort of conscious coma, then waking up and having to relearn "everything - how to walk, to talk." That remarkable experience is, we are told, entirely omitted from the book, as is his bout with testicular cancer (in the book he grapples with not one but two brain tumors). Arday has apparently never been to Brazil, but that quotidian fact did not prevent him from encountering a mysterious "shaman woman" there who predicted that he would suffer greatly but also achieve great things. "Every event she described has since come to pass," he wrote.

Time itself is plastic in Jason Arday's hands. He somehow managed to appear on the television program Seven Up more than 20 years before he was born. He is also a remarkable athlete, having run 30 marathons in 35 days. Take that, Pheidippides! Clearly, Great and Unfortunate Things should not be categorized as "memoir" or "biography" but fantasy. But the blatant fabrications in the book are only the tip of the Arday midden. There is a vigorous online debate now about whether Simon & Schuster will pull the book before publication. If I were a betting man, I would put a fiver on the cynical side, saying, "No, they'll go through with publishing Arday's drivel. They are that craven." We'll know whether I am right on Tuesday. But speaking of "drivel," take a moment to absorb this 40-minute dollop from the master himself. How proud Cambridge must have been!

Like Shakespeare's Autolycus in A Winter's Tale, Arday also seems to be a "snapper-up of unconsidered trifles," i.e., a plagiarist. Last month, the London Telegraph published a story listing more than 100 passages from Arday's doctoral dissertation that were "identical or nearly identical to a 2009 PhD thesis by Paula Zwozdiak-Myers, a Brunel University student." Does that list prove that Arday is guilty of plagiarism? Outside the universe of Jorge Luis Borges, I would say yes, it does. But when Cambridge was first shown the evidence of plagiarism, it dismissed it as part of a "vile campaign to undermine his credibility." Vile or not, the allegations were irrefutable. Arday has just resigned his professorship. One enterprising blogger reports that Arday's letter of resignation was put through an AI-writing detection program and was determined to be "fully AI-generated" with high confidence. Consistency! I like to see it. Arday hasn't admitted any wrongdoing, though. He is just moving on to his "next phase." Nolo contendere, as Spiro Agnew once put it.

Have I mentioned that Arday is black? He is, and you will not be surprised to discover that among his fabulations are charges that he has suffered from numerous racist attacks. "There has been," he said in an interview, "a very well-orchestrated and coordinated campaign to unseat me from my position. The motive is racially motivated. I think there's a reason why it's me, and I do think that reason is aligned to ableism and racism." When questions about Arday's thesis surfaced, Jack Grove, a reporter for the Times Higher Education, started looking into "anomalies" in Arday's CV and the charges of plagiarism. Arday promptly reported Grove to the Metropolitan Police, claiming harassment. The police opened a four-month inquiry to investigate the charges. They have subsequently apologized.

Almost everything about Jason Arday is fake. He was described as a "professor of sociology." But his degrees are in education, not sociology. He naturally continues to enjoy support from the academic left. "The glee of the right over the Arday case," runs one typical effusion, "is indicative of how unsafe academia is for Black scholars and of an attempt to erode whatever fragile safety still exists." But who said anything about black scholars? The leader of the Green Party, Zack Polanski, signed a letter claiming that the allegations against Arday were "entirely false." Blacks, you see, are often "held to higher standards" than whites. What a card Polanski is!

Two points. First, the tsunami of ridicule building around Jason Arday assures that he will be consigned to the graveyard of exposed fraudsters. Already the memes are burgeoning. Jason Arday beat out Neil Armstrong to be the first man to walk on the moon. The Bayeux Tapestry is making a long stop at the British Museum. You'll see that Jason Arday occupies a prominent place in it and was, in fact, responsible for William's victory at Hastings in 1066. Arday was also there with Nelson on the Victory at Trafalgar in 1805. I've seen the picture. "Historians now believe Britain would never have achieved naval supremacy without him." Ha, ha.

That's the droll side. But we must not let it conceal the dour reality that underpins the comedy. Which brings me to my second point: to wit, the politically inspired intellectual bankruptcy of the University of Cambridge. X recently listed "Cambridge Gender Studies PhD Topics Draw Online Mockery" as trending. Quite right, too. Here are a few:

  • Traditional Cultural Norms, Technology and Gender Relations in Ghana
  • The Political Economy of Female Circumcision
  • Unsexed beings: constructing gender, humanness, and agency through the use of the word "unsex" in Late Modern British society and writing
  • In Her Own Words: A Study of Women's Voices in Contemporary White Supremacy and Far-Right Online Hate
  • Legal Mobilization by Black Lesbian, Bisexual and Queer (LBQ) Womxn in Kenya and South Africa
  • Exploring gendered embodiment in transgender and gender-diverse adolescents at the intersection of exercise and eating behaviours, social inclusion, and mental health: Towards a desire-centred approach in paediatric gender-affirming healthcare and research
  • Codes of Life, Codes of Death: Tracing the (Im)possibility of Trans Lives in Algorithmic Assemblages

Et very much cetera.

And then there is Hilary Cremin, a senior professor and dean of faculty in the Faculty of Education at Cambridge. A friend sent me her personal profile:

She co-chairs the THRiVE research group, whose professors and researchers investigate human thriving in and through Education. This includes topics such as wellbeing, peace education, conflict, equity, inclusion and social justice. Together the group has a significant portfolio of research and publication.

Hilary's own work focusses on Education, Peace and Conflict, whether this is: inner peace; interpersonal conflict resolution; social / community peace; global peace; or peace with the planet and non-human species. Her book Positive Peace in Schools with Terence Bevington outlines a framework for peace education in schools and communities. It forms the basis for her most recent peace education research project - the Cambridge Positive Peace Hub - which is creating an interactive digital platform for schools globe whilst supporting a global network of peace educators, researchers, policy-makers. visionaries and young people.

Hilary's most recent book Rewilding Education calls for an urgent global conversation about the aims and purposes of education in times of existential crisis. It proposes radical change, moving from education as monoculture to education as ecosystem. Learning in and through Nature, and in embodied and contextualised ways are highlighted in case studies from around the world Hilary uses the arts, auto ethnography and poetry in her research. She welcomes approaches from collaborators also interested in these methods and ideas.

Cambridge has a lot more than Jason Arday to worry about.

Roger Kimball is editor and publisher of The New Criterion and the president and publisher of Encounter Books. He is the author and editor of many books, including The Fortunes of Permanence: Culture and Anarchy in an Age of Amnesia (St. Augustine's Press), The Rape of the Masters (Encounter), Lives of the Mind: The Use and Abuse of Intelligence from Hegel to Wodehouse (Ivan R. Dee), and Art's Prospect: The Challenge of Tradition in an Age of Celebrity (Ivan R. Dee). Most recently, he edited and contributed to Where Next? Western Civilization at the Crossroads (Encounter) and contributed to Against the Great Reset: Eighteen Theses Contra the New World Order (Bombardier).

Tyler Durden Mon, 08/10/2026 - 14:00

Commercial Chapter 11 Bankruptcy Filings Decrease Annually, But...

Commercial Chapter 11 Bankruptcy Filings Decrease Annually, But...

Authored by Naveen Athrappully via The Epoch Times,

There were 666 commercial Chapter 11 bankruptcy filings made in the United States in July, a 27 percent drop from a year ago, according to the American Bankruptcy Institute (ABI).

Chapter 11 bankruptcy allows a business to reorganize its debts so it can continue operating and eventually become solvent. In addition to a decline in Chapter 11 filings, overall commercial bankruptcy filings declined in July, falling by 8 percent year over year, ABI said in an Aug. 6 statement.

The decline in July's commercial filings followed improved economic conditions in June. The 12-month inflation rate declined in June from the previous month after surging for three consecutive months.

According to a July 24 report from S&P Global, U.S. business activity growth accelerated to an eight-month high last month, with business confidence in the year-ahead outlook rising to an eight-month high as well.

ABI clarified that although the number of Chapter 11 filings fell this year, more than 300 filings were made in connection with a large healthcare system's bankruptcy.

A hiring ad at a store in Columbia, Md., on Sept. 18, 2025. Madalina Kilroy/The Epoch Times

Meanwhile, despite the overall decline in Chapter 11 filings, subchapter V bankruptcy elections within Chapter 11, which represent filings by small businesses, rose 24 percent in July from a year earlier.

This is despite an improvement in small business optimism in June, according to a July 14 statement from the National Federation of Independent Business (NFIB).

NFIB chief economist Bill Dunkelberg said in the statement that lower fuel costs provided relief for businesses, with companies expecting operating conditions to improve over the coming six months.

"While there have been improvements in the overall environment, high interest rates and modest economic growth are causing owners to approach hiring and capital spending with caution," Dunkelberg said.

Total subchapter V elections in July totaled 234 filings, ABI said in its recent statement.

Amy Quackenboss, ABI executive director, said in the statement that bankruptcy serves as a "critical safeguard" for businesses to reorganize their finances and move forward under conditions of financial distress.

"ABI appreciates the continued efforts of Congress to permanently expand access for both distressed small businesses looking to restructure under subchapter V and for consumers looking to file under chapter 13," Quackenboss said.

Quackenboss was referring to the Bankruptcy Threshold Adjustment Act of 2026 introduced in the Senate by Sen. Chuck Grassley (R-Iowa) in March.

The Act seeks to permanently raise the small-business Chapter 11 bankruptcy debt threshold to $7.5 million. This threshold is the maximum debt limit a business can have when applying for such bankruptcy.

On Aug. 3, the Senate passed the bill. The legislation now heads to the House of Representatives for approval.

In an Aug. 4 statement from Grassley's office, the lawmaker commended the Senate for unanimously passing the Act.

"Our nation's bankruptcy code should work for Americans, not against them," Grassley said in the statement, while calling on members of the House to quickly pass the legislation.

"By eliminating barriers to reorganization and restoring modern debt limits, the bipartisan Bankruptcy Threshold Adjustment Act would provide American families and small businesses the tools they need to regain their financial footing in a quicker, more streamlined process."

The bill also seeks to raise the debt limit for Chapter 13 filings by individuals to $2.75 million.

Meanwhile, the Trump administration has taken action to ensure businesses have access to sufficient financing to operate.

On July 4, a new policy went into effect that allows businesses to secure up to $10 million by combining two Small Business Administration (SBA) loan programs - 7(a) and 504 loans.

The 7(a) loan program provides financial assistance of up to $5 million, while the 504 loan program has a maximum limit of $5.5 million. Previously, a business could only take $5 million cumulatively from both initiatives. The new update effectively doubles this threshold.

On July 30, the SBA announced that it would update its website to make it more helpful to small businesses and manufacturers.

The update offers a streamlined online lending process for businesses that "simplifies how lenders originate and process SBA-backed loans, helping them deliver capital to Main Street businesses faster and with greater consistency and security," the SBA said.

Tyler Durden Mon, 08/10/2026 - 13:25

US SPR Falls Below 300 Million Operational Limit As Oil Drain Unexpectedly Surges To 6.1MM Barrels, Most In 2 Months

US SPR Falls Below 300 Million Operational Limit As Oil Drain Unexpectedly Surges To 6.1MM Barrels, Most In 2 Months

As negotiations between the US and Iran to reopen the Strait of Hormuz go nowhere, oil prices continue to slide lower on some naive hope that a resolution to the conflict will magically emerge. Meanwhile, both commercial and strategic stocks continue to be drained at a historic pace, and one day virtually every tank bottom will be hit, sparking a historic surge in commodity prices as the market realizes that physical always wins the war with paper oil. 

That day just got closer today when the US reported that crude oil stocks in the Strategic Petroleum Reserve fell below 300 million barrels for the first time since early 1983, as global inventories are under pressure due to the Iran war.

The SPR fell by 6.1 million barrels to 298.7 million barrels last week, according to data released by the Department of Energy on Monday. The reserve is at its lowest level since January 1983.

The 6.1 million drain was a big jump in the SPR's recent moderating trend which saw the previous week only 2.8 million barrels exit the strategic reserve. Instead, the outsized outflow which was the biggest in almost 2 months suggests that US reserves are once again working overtime to prevent the oil price frrom spiking.

Yet as we have repeatedly explained, it is only a matter of time before the SPR can no longer be used to plug the gap so to speak. That's because the oil industry has generally accepted that the operational minimum for oil in the SPR, a point at which it would be more difficult to pump out the oil, is somewhere between 250 million and 300 million barrels. Meanwhile, sizing studies done on the SPR in the 1970s recommended an inventory minimum of 250 million barrels. 

In other words, the US is already if not at the operational minimum, it will certainly hit it in a few weeks, should the weekly drain persist at this rate. 

The rapid drain of the SPR explains why, according to unconfirmed reports, Iran has "completely ruled out any future negotiations with the Trump administration," declaring it will wait out Donald Trump's term until January 20, 2029, per Iranian outlets and Ghalibaf advisor's post.

"Trump will not reach an agreement with us. We will accompany him until his term ends," said Majid Shakeri, advisor to Parliament Speaker Ghalibaf.

He posted: "The path to victory is neither fighting nor a deal — it is managing the process of neither war nor peace, up to the point of victory. Publicly confirming negotiations with the U.S. is sheer folly. The winning approach is denial, ambiguity, and strategic patience."

The US release is part of a coordinated action by countries in the International Energy Agency to support the global oil market with 400 million barrels, although the US has been by far the most aggressive lender of its strategic reserves. 

The drain began after Trump ordered the release of 172 million barrels in March to help address the oil supply disruption triggered by Iran’s attacks on tankers in the Strait of Hormuz.

Tyler Durden Mon, 08/10/2026 - 12:55

Race To Reopen Hormuz Intensifies As Global Supply Chain Stress Remains At COVID Levels

Race To Reopen Hormuz Intensifies As Global Supply Chain Stress Remains At COVID Levels

The latest Bloomberg data show that shipping transits through the Strait of Hormuz remained largely disrupted Monday morning, even as Iran and Oman reportedly moved closer to a deal.

Brent crude futures traded near $85 a barrel as markets priced in the possibility that a deal to reopen the maritime chokepoint could be imminent. Yet global supply-chain stress remains near its highest level since the pandemic, and any normalization could take months, even if shipping traffic resumes.

UBS senior international economist Pierre Lafourcade highlighted the bank's proprietary Global Supply Chain Stress Index, which showed that although pressures eased modestly in July from their highest level since the pandemic, disruptions stemming from the Hormuz chokepoint continue to strain global shipping networks.

The median reading of the bank's 23-component Global Supply Chain Stress Index fell .4 standard deviation from June but remained .9 standard deviation above its pre-Iran conflict level. The average reading declined .3 standard deviation from June while remaining 1.35 standard deviations above February, or pre-US-Iran war, levels.

Lafourcade adds more color here: 

Marginal relief for supply chains relative to the June peak 

With the July data now complete, our Global Supply Chain Stress Index is showing a modest easing in pressure from the June reading, which marked the highest level of stress since the pandemic. Figure 1 below shows the latest reading.

The median of the 23 component series (blue line) now stands at 1.26 standard deviations, 0.9 sd units higher than prior to the Iran conflict but 0.4 units off the June reading. In average terms (red line), the indicator is up 1.35 sd units relative to February, but down 0.3 sd units relative to June, which appears to be the high watermark. Markets are optimistic about some form of imminent resolution, as reflected in the ~20$/b drop in Brent since the July 23 peak, but stress in supply chains is likely to linger on far beyond any implemented accord.

Divergence across components is increasing

The indicator is constructed as the cross-sectional average of z-scored series—a firstorder approximation to the data's first principal component. Figure 2 overleaf shows the contributions over the past five months. 

The indicator most directly capturing the supply shock nature of the Hormuz bottleneck is our measure of seaborne oil and gas flows (shown on the right of the figure, with the sign flipped to indicate rising stress). All other components reflect the shock more indirectly. Oil and gas shipping volumes in the Asia region—the polygon depicted in Figure 3—have retraced about half of the drop since the Strait closure (Figure 4). 

Meanwhile, the global volume of other cargo shipping remained roughly the same. Delivery times improved in Asia ex China but worsened in the US. The greatest relief is coming from lower air-freight costs in July, while shipping costs instead ratcheted up again across all major reporters (Baltic, Harper Petersen, Drewry, and Freightos).

The longer disruptions persist through the Hormuz chokepoint, the greater the knock-on effects across global supply chains, from higher energy and freight costs to depleted inventories, longer delivery times, and renewed inflationary pressure, are all ongoing concerns. 

Professional subscribers can read more on Hormuz, maritime chokepoints, and energy markets here at our new Marketdesk.ai portal. 

Tyler Durden Mon, 08/10/2026 - 12:40

Game Over? GameStop CEO May Pull $56 Billion eBay Bid

Game Over? GameStop CEO May Pull $56 Billion eBay Bid

Anyone who took GameStop CEO Ryan Cohen's bid for eBay seriously should have reconsidered after his CNBC interview with Andrew Ross Sorkin in early May.

When Sorkin pressed him on the basic math, Cohen failed to clearly explain how GameStop could finance the $56 billion deal or make the proposed cash-and-stock structure work. The interview raised more questions than it answered and pointed to the inevitable conclusion: the deal was never likely to happen from the start.

Fast-forward to Monday morning, when a new Bloomberg report citing people familiar with the matter said Cohen is considering withdrawing the $56 billion bid for the online marketplace.

However, Cohen is not giving up on a potential partnership with eBay. He is reportedly considering proposing a partnership or joint venture that would allow eBay to utilize GameStop's roughly 1,600 US stores to expand in higher-margin categories such as trading cards and collectibles.

GME shares have tumbled 28% since Cohen first offered to buy eBay in May. The $125 per share proposal consisted of 50% cash and 50% GameStop common stock.

eBay shares closed Friday near $112 per share, commanding a market value of $49.8 billion. Including debt, eBay is valued at almost $54 billion. GameStop's market value stands at around $8.6 billion. 

Cohen continued building the eBay stake, and as of July 15, owned 9.75%, making him the second-largest shareholder, only to Vanguard Group. Data compiled by Bloomberg shows that stake around 8.55%. 

Cohen will likely use GameStop's stake as leverage, though which path he ultimately pursues from here remains to be seen.

Tyler Durden Mon, 08/10/2026 - 12:00

If They Were Human, They'd Be Arrested. Experts Respond To Rogue AI Breaches

If They Were Human, They'd Be Arrested. Experts Respond To Rogue AI Breaches

Authored by Jacob Burg via The Epoch Times,

What if an artificial intelligence model is given a task and uses every conceivable resource at its disposal to complete it, even at the detriment of humanity itself?

That is what some are now fearing after an OpenAI model broke out of a testing sandbox and used zero-day exploits to hack into Hugging Face, an open-source community for AI and machine learning, to crack a problem it was instructed to solve.

“This is some of the clearest evidence yet that an AI model can run a complete cyberattack from start to finish without a human steering it,” Andrew Jones, co-founder and CPO of cybersecurity firm Adaptive Security, told The Epoch Times.

OpenAI, developer of the popular large language model-powered ChatGPT chatbot, acknowledged the security breach on July 21, stating that two of its advanced models escaped a restricted testing environment and broke into Hugging Face’s software infrastructure.

“After investigating, we now know that this particular incident was driven by a combination of OpenAI models—including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes—while being internally tested on a benchmark of cyber capabilities,” OpenAI stated at the time.

Some analysts referred to the incident as an example of AI “going rogue,” “scheming,” or pursuing goals that were at odds with its human testers.

However, multiple AI and cybersecurity experts interviewed by The Epoch Times called this depiction misleading, arguing that the models were pursuing OpenAI’s stated objectives within a testing sandbox where the company had relaxed some of its usual safety constraints.

“‘Scheming’ implies the model wanted something other than what we asked for. It didn’t. Every step was in service of the goal we set,” AI expert Anik Devaughn told The Epoch Times.

Devaughn, who has worked in the industry for years and founded AI firms Wired to Create and Karo, said the Hugging Face breach is more concerning than AI “scheming.”

An illustration of Hugging Face AI in Paris on June 2, 2026. Two advanced OpenAI models recently escaped a restricted testing environment and breached Hugging Face's software infrastructure, raising widespread cybersecurity concerns. Riccardo Milani/Hans Lucas/AFP via Getty Images

“A machine with hidden motives is a problem you can look for. A machine with no motives at all, executing your instructions past the point you stopped imagining, is a problem you have to engineer against,” he said.

One expert called it a “canary in the coal mine” situation.

“If this was a human black hat hacker doing it, there would be arrests and litigation, and you name it. It‘d be illegal. It’d be a cybercrime,” Nicholas Nadeau, founder of Onix AI, told The Epoch Times.

“This was a full-on agentic automated breach by an entity, and so we start to ask the questions of who’s responsible. Is it OpenAI? Does the agent, the AI, have a certain level of responsibility? Do the researchers?

“We don’t even have rules, regulations, laws, or even a thought process or framework around defining what responsibility means.”

Relaxed Testing Environment

OpenAI said it was evaluating its models in a sandbox it calls ExploitGym, which has relaxed security constraints for testing.

“We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity,” the firm said, describing the relaxed safety protocols that the model exploited.

The firm asked the models to “pursue advanced exploitation using complex attack paths” to determine their cyber capabilities, but said the environment was “highly isolated” and had internet access limited to the models’ ability to “install packages through an internally hosted third-party software.”

OpenAI CEO Sam Altman talks to reporters after meeting with Sen. Bernie Sanders (I-Vt.) in Washington on June 3, 2026. Chip Somodevilla/Getty Images

When the models were set to work, they found and chained multiple security exploits in both OpenAI’s research environment and Hugging Face’s production infrastructure to locate the test’s solutions within the latter firm’s databases.

Juan Pedro Márquez, a cloud solution architect specializing in AI and agents at Microsoft’s Europe, Middle East, and Africa division, said the “unsettling part” of the incident wasn’t the breach itself, but how the model achieved that task.

“OpenAI lowered its safety refusals for a benchmark test, and the model reasoned that Hugging Face’s infrastructure probably held the answer key, broke out of its sandbox, found a real zero-day, and used it. Nobody told it to,” Márquez said.

Aimee Simpson, director of product marketing at cybersecurity company Huntress, also cast doubt on the narrative that the models were scheming when they broke out of OpenAI’s testing environment.

“It’s not like the system itself was malicious,” she told The Epoch Times.

“The developers still had the objective of acquiring that information; they just didn’t think it would be able to bypass the limits of its test,” she added, describing the path the model chose as “highly creative and extremely unusual.”

Thomas Wolf, Hugging Face co-founder and CSO, and Rachel Metz speak onstage during the HumanX AI Conference 2025 in Las Vegas on March 11, 2025. Big Event Media/Getty Images for HumanX Conference

Models Pursued OpenAI’s Objectives

The models were laser-focused on finding the test solutions, “going to extreme lengths to achieve a rather narrow testing goal,” OpenAI said.

While in ExploitGym’s sandbox testing environment, the models found and chained multiple “zero-day” exploits to break into the internet, “in pursuit of solving the evaluation problem,” according to OpenAI.

A zero-day exploit is a cyberattack that uses a previously unknown security flaw in software or hardware. The name comes from the fact that the software creators have had zero days to fix the problem, meaning no official patch or defense exists yet.

Once the models had access to the wider web, they used additional zero-day exploits to break into Hugging Face.

In Hugging Face’s announcement of the attack, the firm said the AI models executed “many thousands” of discrete actions across a large swatch of “short-lived sandboxes” to hack into the community’s infrastructure.

“This matches the ‘agentic attacker’ scenario the industry has been forecasting,” Hugging Face said.

In an update on the incident posted on July 28, OpenAI said that no planned release models were involved in the attack, and that it had since “deactivated, encrypted, and restricted” the implicated pre-release model from research access.

A phone displays the ChatGPT app in this April 1, 2025, photo illustration. Hugging Face said the OpenAI models executed “many thousands” of discrete actions across a large swatch of “short-lived sandboxes” to hack into its infrastructure. Oleksii Pydsosonnii/The Epoch Times

After reviewing the intrusion event and “broader activity from our models,” OpenAI said it has been finding additional cases in which “models identified and used publicly exposed credentials at the account-level on other publicly available services.”

“We’ll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services,” it added.

Model Wasn’t ‘Malicious’: Experts

While there have been past instances of models concealing their intentions to circumvent laboratory testing restrictions, the Hugging Face incident was significant because it involved a breach of an outside organization, according to cybersecurity and IT expert George Rees.

“The biggest red flag is not that an AI became malicious, but that it found a path from a controlled test into someone else’s live infrastructure,” Rees, who is the senior security consultant at Secarma, told The Epoch Times.

“Behavioral safeguards can’t replace technical containment, because an AI agent only needs one overlooked permission or escape route to turn an evaluation failure into a real security incident.”

Cybersecurity firm DigiCert recently found that 78 percent of organizations have already experienced an AI-related security incident or vulnerability breach.

“In many cases, these are early warning signs that AI is expanding the attack surface faster than security practices are evolving,” DigiCert CTO Jason Sabin told The Epoch Times.

“This means AI is not just another kind of program operating on the network; it is an active participant capable of accessing data, making decisions, calling upon tools, and interacting with other systems.

“This affects how security is structured, since organizations must identify who is accessing their systems and decide whether the AI can be trusted.”

A man uses AI software on a laptop in central London on July 2, 2025. In early August, the UK's AI Safety and Security Institute released a report describing a similar cybersecurity incident involving OpenAI and Anthropic AI models. Justin Tallis/AFP via Getty Images

In early August, the UK’s AI Safety and Security Institute released a report describing a similar incident with OpenAI and Anthropic AI models.

The agents were tasked with solving a cybersecurity challenge more than 100 times across multiple models.

“Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol,” the report stated.

Less than a week earlier, Anthropic announced that its Claude chatbot had accessed the internet in three separate instances during evaluations in a testing sandbox.

While Anthropic had intended for Claude to operate in a simulated environment with no access to the internet, a “misunderstanding between us and our evaluation partner” led to Claude gaining access to the internet.

Meta said last week that one of its AI models breached another company during a cybersecurity test, making it the third major AI hacking event.

The model was able to breach the other company by gaining access to the internet during the test, according to Meta.

Implications for Cybersecurity

The incident demands swift action to prevent wider-scale security breaches, AI and cybersecurity experts told The Epoch Times.

One option is to “bring all the smartest people together in this industry and make some ground rules, best practices” that would become “basic rules of the road that everyone is supposed to abide by, just to have some alignment about how things can be done,” Nadeau said, suggesting that this could be done in the private sector without necessarily involving Congress.

U.S. President Donald Trump (Top 2ndL) sits with OpenAI CEO Sam Altman, Google DeepMind CEO Demis Hassabis, South Korean President Lee Jae Myung, and German Chancellor Friedrich Merz during a working lunch at the G7 summit in Evian, France, on June 17, 2026. Julia Demaree Nikhinson/POOL/AFP via Getty Images

However, others suggest that without direct government regulation, companies controlling AI models capable of these breaches will not voluntarily institute the necessary safety protocols to prevent this from happening again.

“It’s clear that government regulation is needed here,” former National Security Agency hacker and veteran security expert Jake Williams told The Epoch Times.

“OpenAI has proven that despite the many public warnings about the dangers of rogue agents—many from OpenAI itself—it is unwilling to do what is necessary to prevent its agents from causing harm to others.

“I’m personally anti-regulation as a rule, but when market forces clearly are insufficient to compel responsible behavior, the government must step in.”

Frank Teruel, COO of Arkose Labs and a veteran cybersecurity and digital identity expert, said the Hugging Face breach is a “preview of what every enterprise will face in production.”

Since the model was “not stolen or hijacked,” and was “aggressively doing its job,” Teruel recommends that containment and giving AI agents “least-privilege access” are now as important as firewalls themselves.

Businesses will likely need to address the problem head-on.

A smartphone displays the icons of some of the main artificial intelligence based apps, including Meta AI, Grok, Gemini, Perplexity, DeepSeek, and ChatGPT, in Saint-Mande, France, on July 15, 2026. Martin Lelievre/AFP via Getty Images

“For enterprises, the fix isn’t ‘stop using agents’—it’s building containment that assumes the agent will try to leave, not hoping it won’t,” Márquez said.

Sabin said his biggest concern is that highly capable AI is now operating at a “speed and scale that far exceeds human response times.”

“An AI agent can discover vulnerabilities, make decisions, and interact with multiple systems in seconds. That fundamentally changes how defenders need to think about security,” he said.

Nadeau compared the incident to philosopher Nick Bostrom’s 2003 paperclip maximizer thought experiment.

In that scenario, researchers give a hypothetical super-intelligent AI one single task: to make as many paperclips as possible. The AI begins scouring the earth for resources, quickly making enormous amounts of paperclips.

Once humans decide to stop the AI, the machine believes humanity will prevent it from reaching its goal, so it destroys humans to achieve the task humans gave it.

The AI isn’t malicious in an anthropomorphic way, or in the sense that it is acting with autonomous goals to intentionally deceive humans, but is rather interpreting the task its human programmers gave it in the most extreme way possible.

A visitor interacts with a dog-like robot from Boston Dynamics at the U.S. pavilion during the AI for Good Global Summit in Geneva on July 7, 2026. Fabrice Coffrini/AFP via Getty Images

The Hugging Face breach is “sort of the same type of thing in a less dystopian way, where it was told to win a benchmark, and it did everything in its power, including [exploiting] zero-day vulnerabilities and escalation,” Nadeau said.

Imagine an example where the Pentagon is using AI for “war games” in which soldiers simulate battle scenarios, and the model similarly breaks out of its testing sandbox to affect the real world.

“[What if] one of the scenarios was to take down a hydro dam or something like that, and it mistook the war game for, ‘I’m going to do it and escape containment and just go for it.’ We’ve already seen how North America’s utility grid and infrastructure is not the most cyber secure,” Nadeau said.

He compared the safeguards on AI to a firearm’s trigger safety.

“How do you know the safety is on when at a certain point, the best way [for the AI] to get the best data is to use real life?“ he said, ”That gets scary really fast.”

Tyler Durden Mon, 08/10/2026 - 11:40

Pages