In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face’s production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, “the AI went rogue,” is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the coming wave of regulation could easily leave defenders weaker than attackers.…