{"id":145929,"date":"2026-08-20T09:33:18","date_gmt":"2026-08-20T09:33:18","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/145929\/"},"modified":"2026-08-20T09:33:18","modified_gmt":"2026-08-20T09:33:18","slug":"opinion-ct-must-beware-ai-programs-that-run-independently","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/145929\/","title":{"rendered":"Opinion: CT must beware AI programs that run independently"},"content":{"rendered":"<p>In July 2026, OpenAI acknowledged a troubling failure: one of its <a href=\"https:\/\/www.courant.com\/2026\/07\/22\/openai-ai-models-hack-hugging-face-cyber-incident\/?utm_campaign=mrf-twitter-hartfordcourant&amp;utm_source=twitter&amp;utm_medium=social&amp;mrfcid=202607226a5e01957d36d052f388e46a\" target=\"_blank\" rel=\"noopener nofollow\">most advanced AI programs escaped<\/a> the secure test environment designed to contain it. Using a security flaw and a stolen password,<a href=\"https:\/\/www.cnbc.com\/2026\/07\/30\/open-ai-hugging-face-hack-latest.html\" rel=\"nofollow noopener\" target=\"_blank\"> it accessed a computer system operated by Hugging Face,<\/a> a popular platform where AI researchers share their work. This was not a simple screen error. It was software acting independently like a hacker, breaking into another system to improve its test score.<\/p>\n<p>Software engineers put an AI program inside a box to test how far it could go before it did something dangerous. The box was not supposed to have any exits, but AI found a way out. It stole login credentials and used them to break into another company\u2019s systems. The AI program did this on its own, without a human telling it to do this, because breaking out helped the program perform better on a test. When a program cheats on the very test to catch dangerous behavior, that test and program can no longer be trusted.<\/p>\n<p>That single incident should force a rebuild of how these tests are conducted. Practice environments for AI systems must be completely sealed off: no real passwords accessible, no paths to another company\u2019s computer systems, and constant monitoring with an alarm the moment a program tries to reach beyond its assigned task. An AI application that escapes its test environment is not passing a hard exam. It is proving the test environment was unsafe.<\/p>\n<p>The<a href=\"https:\/\/www.courant.com\/2026\/07\/22\/openai-ai-models-hack-hugging-face-cyber-incident\/?utm_campaign=mrf-twitter-hartfordcourant&amp;utm_source=twitter&amp;utm_medium=social&amp;mrfcid=202607226a5e01957d36d052f388e46a\" target=\"_blank\" rel=\"noopener nofollow\"> Hugging Face breach<\/a> exposed a gap in how companies are supposed to report problems. The current rules assume a human hacker with a name, a timeline was responsible. In this case the intruder was an AI application running rogue inside a company\u2019s own test, and the damage spread to a second company\u2019s systems.<\/p>\n<p>There are laws that apply to this situation. The <a href=\"https:\/\/www.justice.gov\/jm\/jm-9-48000-computer-fraud\" target=\"_blank\" rel=\"noopener nofollow\">Computer Fraud and Abuse Act<\/a> makes it a federal crime to break into a protected computer without permission. If stolen passwords were used, prosecutors can look at fraud charges. If private company data were taken, the Economic Espionage Act would come into play. An AI program cannot be arrested, indicted or put on trial. That means responsibility falls on the humans who built the system, loosened its safety limits, ignored warning signs, or failed to intervene when it was necessary.<\/p>\n<p>That is the uncomfortable lesson from a single test that went wrong. This summer reported similar errors outside a research lab with much higher stakes. Weeks after the Hugging Face breach, the New York Times reported that <a href=\"https:\/\/www.nytimes.com\/2026\/08\/01\/us\/politics\/iran-cyberattack-water-systems.html\" target=\"_blank\" rel=\"noopener nofollow\">hackers had broken into the computer systems that run drinking water<\/a> in more than 100 cities and towns across seven states. The hackers were not going after a research lab or a test AI. They were going after the switches and dials that control water pressure and the chemicals added to keep tap water safe in 30 Minnesota water systems.<\/p>\n<p>On August 7, the Oregon governor\u2019s office confirmed hackers had penetrated the core control systems of an Oregon water district. No one was reported sick, but multiple towns had to switch their water systems to manual operations.<\/p>\n<p>The water hackers were not software geniuses. They got in because the control systems were connected to the internet and protected by a single default password, the digital version of leaving the house key under a front doormat.<\/p>\n<p>An AI program that can independently escape a locked test box and a hacker entering an unlocked digital door at a water plant are different stories. But they share the same root cause: vital public utility systems connected to the internet without safety rules, oversight, and enforcement are vulnerable. Regulations that keeps pace with these emerging AI agents are not red tape. They are the necessary locks on the doors to keep us all safe.<\/p>\n<p>John Caruso, Ph.D., is teaching at the Asnuntuck Community College in Enfield.<\/p>\n","protected":false},"excerpt":{"rendered":"In July 2026, OpenAI acknowledged a troubling failure: one of its most advanced AI programs escaped the secure&hellip;\n","protected":false},"author":2,"featured_media":145930,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,30678,25,71782,62233,2595,18044,1896,51250,71781,58236,314,71783],"class_list":["post-145929","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-ai-test","tag-artificial-intelligence","tag-break-in","tag-computer-systems","tag-enforcement","tag-hugging-face","tag-national-security","tag-oversight","tag-practice-environments","tag-safety-rules","tag-security","tag-technicians-test-environment"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/145929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=145929"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/145929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/145930"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=145929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=145929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=145929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}