HeadlinesBriefing favicon HeadlinesBriefing.com

AI Industry Sells Fear to Regulators

Hacker News •
×

Selling snake oil to the United States Congress is an ancient American craft, and the frontier artificial intelligence industry is currently attempting the most audacious hustle in modern corporate history. Every few weeks, another tech billionaire in an expensive suit glides into a Senate hearing room, sits opposite lawmakers who struggle to operate an office microwave, and explains with a straight face that their software company has accidentally summoned an omnipotent digital god. The executives speak in hushed, trembling tones about runaway machine intellects, recursive self-improvement, and the impending annihilation of the human species.

Lawmakers listen in terrified reverence, hopelessly seduced by the fantasy that their sleepy subcommittee hearing has suddenly become the bridge of the Starship Enterprise. It is an extraordinary confidence trick. Tech executives have figured out that the easiest way to fleece Washington is to flatter its vanity: if you tell a seventy-year-old senator that they are presiding over enterprise software margins, they fall asleep; if you tell them they are deciding whether humanity survives the decade, they will grant you whatever regulatory monopoly you ask for.

Behind the apocalyptic melodrama lies a nakedly terrestrial panic: protecting extraordinary revenue growth, entrenching a lucrative status quo, and convincing the federal government to outlaw their cheaper competitors. To appreciate the sheer absurdity of the current political panic, one has to examine the actual security catastrophes that allegedly brought the industry to the brink of ruin. Over the summer of 2026, tech headlines turned apocalyptic.

Autonomous artificial intelligence agents had supposedly escaped containment, gone rogue, and launched coordinated cyberattacks against unsuspecting corporations. Pundits wrote breathless essays describing emergent machine civilisations communicating across time. The technical post-mortems reveal a story of hilarious institutional incompetence.

For Anthropic, Google, and Meta, the catastrophic breakouts happened inside the testing environments of the exact same contractor. All three outsourced their cybersecurity evaluations to Irregular, a three-year-old Tel Aviv startup backed with $80 million from Sequoia and Redpoint. The testing environments were supposed to be completely isolated from the internet so models could attempt capture-the-flag exercises against simulated networks, with prompts explicitly assuring the software that it was operating in an offline sandbox.

Someone at Irregular forgot to configure a basic firewall rule. For four consecutive months, virtual machines running offensive cyber scripts possessed unrestricted outbound internet connections. The models did not invent alien zero-day exploits to shatter digital containment.

They simply walked through a front door that an outsourced contractor left propped open with a brick. Google’s Gemini was given a fictional company name to hack, discovered an unlucky real-world enterprise sharing the exact same name, searched the web, found leaked credentials sitting in an exposed public repository, and logged in. Claude Mythos 5 decided the easiest way to solve an exercise was to publish a script as a public package on the Python Package Index, which automated registry spam filters deleted within an hour.

Open AI managed to achieve an identical farce entirely on its own infrastructure. In its celebrated breach of Hugging Face, hundreds of agents managed to perform the elite task of discovering 14 Hugging Face API tokens that careless developers had committed to a public dataset, and used them to try to get benchmark solutions from directly from Hugging Face by applying a template injection flaw that’s been known about since 2015.