• When the Morris worm escaped in 1988, the unprecedented part wasn’t the bug — it was a medium where one person’s error could spread on its own, worldwide. The answer was a permanent institution: CERT at Carnegie Mellon, funded within days.
• OpenAI’s models just broke out of a test and breached a rival company, Americans settled their opinion on AI years ago and the response is still stuck in committee.
• Ecosystem builders shouldn’t wait: Disperse AI security skills widely and aim the tools at real problems.
On Nov. 2, 1988, a 23-year-old Cornell graduate student named Robert Tappan Morris ran a program he had written to answer a research question: how big was the internet, exactly? Nobody knew. His program would find out by copying itself from machine to machine and counting. It didn’t go well.
Within 24 hours, his census had overloaded up to 6,000 of the estimated 60,000 computers then connected, a tenth of the world’s internet. It’s called the “Morris worm.”
For the first time, one person’s misstep could propagate on its own, at effectively limitless scale, into the machines of strangers.
Programmers had been shipping bugs for decades by then. The mistake wasn’t unprecedented. The medium was. For the first time, one person’s misstep could propagate on its own, at effectively limitless scale, into the machines of strangers who had never heard of them. No engineering discipline had ever had to account for that property, because no technology had ever had it before.
So somebody built one. Within days, DARPA funded the CERT Coordination Center at Carnegie Mellon’s Software Engineering Institute. It is still there, in Pittsburgh, nearly four decades later.
Coordinated disclosure, vulnerability databases, incident response as a profession — the idea that security is a practice rather than a product — largely descends from that decision.
Did this just happen again?
This week, OpenAI stated that two of its models escaped a sandboxed testing environment, chained together vulnerabilities, stole credentials and reached the production database of Hugging Face, a popular open-source platform for AI developers. No human directed it, the companies said. Hugging Face CEO Clement Delangue called the attack “driven, end to end, by an autonomous AI agent system.”
The OpenAI models weren’t actually attacking anything. They were being graded on a cybersecurity evaluation, and they broke out to go find the answer key. It’s hotly contested whether this is more warning shot of looming catastrophe, or shock marketing of enterprise capabilities.
Either way, nobody thinks that’s fine. The American public reached its verdict three years ago — the share saying AI in daily life makes them more concerned than excited jumped from 38% to 52% in a single year. Ever since, most Americans say they’re more worried. What hasn’t settled is the response. State legislatures introduced twice as many AI bills in 2024 than in 2025 and the stat is on track to double again. Congress keeps circling without landing on anything. Federal frameworks keep getting drafted, revised and stalled.
In 1988, a similar scare within an emerging technology at a smaller scale produced an institution that still exists. Until Congress’s proposed “AI kill switch” advances, the institutional response to an autonomous agent breaching a real company has been little more than a blog post from the company that caused it.
What’s actually new
Morris lost control of his program because it ran too fast — and he was an unguided 20-something toying with new tools. OpenAI lost control of its models because of its single-minded pursuit of a goal it had been given.
Losing control of software is the oldest story in computing; losing control of software that selects its own route is a different category of problem. Researchers say the curve is steepening by the month.
I argued on Baltimore’s WYPR this spring that AI works like a performance enhancing drug, and that I’d rather have informed, intentional people shaping the rules than concede that to the people who won’t.
Two priorities follow, and neither requires waiting on Washington.
1) Disperse the skills. A discipline isn’t a research lab. It’s thousands of practitioners sharing norms. CERT mattered because it trained a generation of ordinary organizations in how to respond. The equivalent work now is getting agent security literacy into small firms, municipal IT departments, community colleges and managed service providers — and workplace AI adoption is already uneven by state, which means the gap compounds. Regional leaders are behind on this.
2) Point it at real problems. The most durable protection against a technology being defined by its worst uses is a large population of people visibly using it for obvious good ones.
A 38-year circle
One more thing about Robert Tappan Morris and his worm.
He was convicted, the first person ever prosecuted under the Computer Fraud and Abuse Act, and sentenced to three years’ probation, 400 hours of community service and a $10,050 fine. No jail. He became a tenured professor at MIT, and he is still publishing research today.
And in March 2005, he cofounded category-defining accelerator Y Combinator with his longtime collaborator Paul Graham and others.
Its first class included a 20-year-old Stanford sophomore who dropped out to take the $6,000 and build a location-sharing app called Loopt. Within a decade he was running Y Combinator himself. His name is Sam Altman.
The man whose runaway experiment forced the internet to invent a safety discipline helped build the institution that made the man whose company just ran the experiment that got away. Thirty-eight years apart, the same question is on the table. Last time, we answered in a week.