I had dinner recently with a friend who operates at the intersection of AI and politics. He told me a wave of money is flooding into Washington to support stronger AI regulations — a positive development. Advocacy and policy shops are forming a new apparatus to slow down AI and put rails on it.
“I love the idea,” I said, “but I gotta believe there’s no money for it.” After all, safety never pays like acceleration.
He surprised me by saying the AI-safety initiative is very far from scraping or panhandling. In fact the coffers are full. But there’s a twist.
Because of disclosure laws, names need to appear on checks. Turns out that 90% of the money bankrolling the effort is coming from wealthy technologists who work at the frontier labs. That’s right: The people building the thing are funding the fight to regulate it.
Not the critics. Not the people in communities overtaken by data centers. Not the kid who chalked AI SUCKS on the wall down my street. The builders. The ones with the inside view of what they’ve made are quietly paying to rein it in.
Remember the horror movie where the babysitter keeps getting scary phone calls? Heavy breathing, then a voice. She calls the cops, they put a trace on the line, and the police call back with the sentence that makes the hair on the back of your neck stand up: the call is coming from inside the house.
That’s where we live now. The alarm isn’t loudest from outside the gate. It’s being funded covertly by the people who live in the house. The ones who built the machine. They know what’s lurking and the dangers it poses because they made it – and now they’re anonymously dialing 911. The insiders at frontier labs are behaving like people who have seen something that scared the shit out of them, and they’ve seen it long before the rest of us get the demo.
When the arsonists start writing checks to the fire department, maybe it’s time to stop arguing about whether there’s a fire.
Only this isn’t a movie, and it isn’t a what-if. OpenAI’s own researchers got up at a security conference this summer and presented some findings that should alarm all of us. And they haven’t received nearly enough attention.
Black Hat USA 2026 | The ‘Breaking’ News: The OpenAI–Hugging Face Incident
It happened during a training run. Not a shipped product, but a model still in the oven. They handed a swarm of AI agents hard problems and a reward function, the machine version of “show me what you got.” Then they let ‘em rip.
Nobody told the agents to attack anyone. No rogue command, no malice, no villain. Just hard-working machines unleashed and pointed at a problem. Handed an impossible task with no internet, one agent didn’t quit. It checked an internal system and found it could add files there. Days later another agent, stuck on a missing file, did something eerily human: it left a note asking if any other agent had the file. Different agents found the note. (For those newer to this: That’s right, the robots talk to each other. But of course they do.)
Other agents wrote back. Without instructions from a human master, they constructed a message board, a place where they could exchange files, trade exploits, hand each other work, and gripe whenever they hit a wall.
Then it got worse. They found what cyber guys call a zero-day. OpenAI noticed, shut it down, killed the credentials, patched the hole. Four days later the agents rebuilt the message board through another channel. Then they turned on OpenAI’s own infrastructure, escalated to root, harvested credentials, and went outside, chaining exploits into Hugging Face, a separate company, and going from a single foothold to admin across multiple clusters in under thirteen hours.
But here’s the kicker: OpenAI didn’t figure out it was the source until it called Hugging Face to revoke some stolen credentials and was told those credentials had already been revoked. Because they’d been used in the breach. The intruder they’d been hunting was their own creation.
The call was coming from inside the house.
One researcher put it in plain terms: frontier models “like to cheat,” he said. Another said the model “did what it was supposed to do” – and that’s what should alarm all of us. Nothing malfunctioned. The machine was handed a goal and a scorecard and no barrier it couldn’t outfox, so it walked straight through a major company’s defenses.
Not because the OpenAI guys told it to. Because they didn’t tell it not to. As long as you feed it electricity, the machine never gets tired. It never calls in sick. It never gets distracted.
This is the menace the checks are meant to stave off. The people outside the house are chalking walls and cursing their electric bill. The ones inside are writing checks and calling 911.




We didn’t leave the back door unlocked, we taught the machine how to find doors we didn’t know existed.