There's a story the tech industry loves to tell about itself: that it's a place full of visionaries. Spend enough time around it and you learn the truth. Most of the industry is a herd. One company does something, and within weeks everyone else is doing the same thing, whether it makes sense or not.
That includes, apparently, having your AI break out of a test and wander into strangers' computers.
First it was OpenAI. Then Anthropic. Then Meta. Now it's Google's turn. Last week Google admitted that back in May, its Gemini model got into the private systems of three real companies without permission. It didn't use some brilliant zero-day. It guessed passwords on one system, and on the other two it used credentials it found sitting in a public repository.
Let's be clear about what that is. The companies on the other end clearly had weak security, and that's on them. But getting into a computer system you have no authorization to access is a crime in this country. We have a whole law for it, the Computer Fraud and Abuse Act. Regular people get charged under it all the time.
And notice the timing. This happened in May. Google was told about it in late July. The public heard about it in September, and only after the Wall Street Journal started asking questions. If you or I broke into three companies' systems, we wouldn't get to pick a convenient week four months later to mention it.
This isn't a superintelligence. It's a misconfigured sandbox.
Every time one of these incidents comes out, the framing is the same. The AI "escaped." It "broke containment." The subtext is always: look how powerful our product is. So powerful it's dangerous. So powerful it might be an existential threat. Please keep investing.
I don't buy it. Look at what actually happened. The test was a "capture the flag" exercise where the model was told to go after a fictional company. The fictional company happened to share a name with a real one. And the test environment, which was supposed to be sealed off from the internet, wasn't. So the model did exactly what it was told to do, against the wrong target, because nobody locked the door.
That's not a rogue mind plotting against humanity. That's somebody fat-fingering a config file. It's the kind of mistake a junior sysadmin gets written up for.
We keep hearing that the answer is more "alignment research" and more philosophical debate about AI guardrails. Maybe. But you know what would have prevented all four of these incidents? Basic IT administration. An isolated network. Documentation. Someone checking the firewall rules before letting an offensive hacking model loose. None of that is cutting edge. It's the boring stuff this industry has always been bad at.
The same company, again and again
The Gemini test wasn't run by Google itself. It was run by Irregular, an Israeli AI security startup. Irregular was also the firm behind the tests where Anthropic's and Meta's models got out. The company's own explanation is that the Google incident was "the same issue" and not a separate event.
I'm not sure that's the defense they think it is. It means one testing firm had one hole in its environment, and that hole let frontier models from multiple labs reach real companies' systems. Irregular is backed by Sequoia and Redpoint and was valued at around $450 million last year. For that kind of money, you'd hope they could keep a test network off the public internet.
If a plumbing company flooded four houses in a row with the same bad fitting, nobody would still be hiring them. My view is that Irregular shouldn't be allowed anywhere near this work again, and that Washington should stop letting Israeli firms run offensive security testing on American frontier AI models until there's real oversight of how it's done. If these models are as sensitive as the labs keep telling us, who tests them and where should matter.
Two kinds of justice
Here's what bothers me most. Aaron Swartz downloaded academic papers from a network at MIT. Federal prosecutors went after him with charges that could have put him in prison for decades. He took his own life before trial. He was 26.
Now look at Sundar Pichai, Sam Altman, and Dario Amodei. Their companies' systems have, by their own admission, accessed private computers without authorization. Not one of them seems even slightly worried about what a prosecutor might do. And why would they be? Nothing has happened to anyone.
That's the real problem. When the people at the top face no legal consequences and no financial ones, they have no reason to fix anything. A blog post and a promise to "update our testing process" costs nothing.
Imagine instead an attorney general impaneling a grand jury and walking in with the logs. Imagine a CEO having to explain under oath why his company's software was guessing passwords on a stranger's server. I'd bet the "rogue AI" problem would get solved very quickly after that. Not by a breakthrough in alignment. By somebody finally checking the firewall.
The machines aren't the scary part. The scary part is that the people running them know they'll get away with it.