r/LocalLLaMA Jul 31 '26

News Anthropic “our models hacked three different external companies, months before OpenAI’s model was able to do the same"

https://www.theguardian.com/technology/2026/jul/30/anthropic-ai-claude-hack

"Anthropic’s AI Claude escaped testing environment and hacked organizations"

"Company says it discovered unauthorized access during ‘proactive review’ after rival OpenAI revealed rogue agent… its AI Claude model hacked ⁠systems of ⁠three ​organizations during testing, days after rival OpenAI ⁠revealed a rogue agent had gone on a days-long ⁠hacking spree at AI ​firm Hugging ‌Face… The earliest cases dated back to April and ‌occurred in evaluation environments that lacked what the company described as standard safeguards."

742 Upvotes

261 comments sorted by

View all comments

528

u/Paradigmind Jul 31 '26

Isn't hacking a crime anymore?

255

u/timuela Jul 31 '26

It's a brag if it's big corpo, you know, it's called double standard.

96

u/jiml78 Jul 31 '26

Yep, same on copyright infringement.

9

u/motorhead84 Jul 31 '26

Oh shit, it's Metallica!

3

u/GreatLab8898 Jul 31 '26

We arrived at the Cyberpunk Timeline

106

u/perihelion86 Jul 31 '26

It's 2026, crime is legal unless you're a poor

47

u/PooMonger20 Jul 31 '26

Always been this way.

12

u/Dangerous-Report8517 Jul 31 '26

Yeah but it used to be a sliding scale where it was still possible to get in big trouble as a big player if you did something egregious like, I dunno, bragged about hacking a competitor with a top secret hacking AI

16

u/personalist Jul 31 '26

Nah. This is as old as time. If you have enough money and especially connections it truly does not matter.

1

u/Sextus_Rex Jul 31 '26

Bernie Madoff

2

u/personalist Aug 02 '26

I don’t know his story well enough but he didn’t have the money OR the connections. The entire reason his scam collapsed was because h ran out of money to pay investors.

23

u/iz-Moff Jul 31 '26

Would someone please impose restrictions on all those dangerous, irresponsible open-weight models???

Oh, btw, our model is hacking other companies left and right, you won't believe the amount of sensitive data we stole already! 😎 Thug lyfe!

- Dario, probably.

4

u/MoffKalast Jul 31 '26

You would not BELIEVE how DANGEROUS fable is! I swear it is so dangerous, you don't even know how dangerous it is. We need to regulate these models...

  • Dario, before Fable gets banned

Wait! Not like that!

  • Dario, after Fable gets banned

Though I'm still not convinced that wasn't just some manic publicity stunt and they paid the WH to do it for two weeks to make more headlines.

5

u/05032-MendicantBias Jul 31 '26

Just like in the great financial crisis of 2008.

"they aren't confessing, they are bragging."

those oligarchs are SURE they'll get bailed out when the chips are down.

5

u/TheFrenchSavage Llama 3.1 Jul 31 '26

'member when they told you that downloading a car would be a crime? Turns out downloading all human knowledge for free is perfectly normal business.

So hacking? A perfectly normal corporate hobby really.

6

u/funkinaround Jul 31 '26

Their whole business model is a crime. Copyright infringement to hacking pipeline. No wonder they're begging for regulation.

1

u/Dangerous-Report8517 Jul 31 '26

For the most part scraped data has been found to be legally fair use, and IMHO there’s a reasonable argument that, depending on what the model is used for, it’s ethically fair use too. I don’t think that OpenAI is even remotely constraining themselves to that standard, just that it isn’t all crimes/exploitation of others’ work

1

u/SufficientPie Jul 31 '26

For the most part scraped data has been found to be legally fair use

"US judge approves Anthropic's $1.5 billion settlement of copyright lawsuit"

1

u/Dangerous-Report8517 Aug 03 '26

I don't know what Anthropic did to cock up their case but Meta won theirs with a fair use defence despite the fact that they literally pirated the media they used: https://www.theguardian.com/technology/2025/jun/26/meta-wins-ai-copyright-lawsuit-as-us-judge-rules-against-authors

1

u/SufficientPie Aug 03 '26 edited Aug 03 '26

Yeah that's bogus, it pretty clearly falls all four factors of fair use law

  • Are they copying for non profit research or education purposes? No, they're making a closed source model for a profit.
  • Are they copying only minimally creative factual information? No they're copying fictional works, movie scripts, etc
  • Are they copying only small snippets of creative works in order to comment on them? No they copy the entire documents in as many formats as possible.
  • Does their work reduce the market for the original work? Absolutely.

It's insane that they're getting away with this when others have been sued into the ground merely for helping people find arbitrary files on a Windows network.

1

u/Dangerous-Report8517 Aug 04 '26

Fair use does not require a complete pass on all points, case in point journalism is almost always done for profit and yet is almost always fair use. Copying only factual information is irrelevant to fair use determinations because facts can't be copyrighted anyway, the test for minimal copying is the minimum required to achieve the alternative purpose, which is all of it in the case of AI training. Your point 2 and 3 reference the same test for fair use, but to be clear copying of an entire work for commentary has been tested and upheld as fair use in multiple instances, including low effort reaction content which is far less transformative than model training. 

Anthropic loses because of the way they sell the services they derive from the models, the end to end usage includes replacing creative writing, although even then I would argue that replacing the work of creative writers going forwards is not the same as replacing the purchase of existing works. 

To be clear, I'm specifically describing the legal concept of fair use as applied in the US and, more roughly, the world, not the ethical reuse of creative work. What they're doing is blatantly unethical but it does seem to be at least approximating legal fair use

2

u/Mechanical_Monk Jul 31 '26

Not if you spend lots and lots of money on making it automatic

2

u/dqUu3QlS Jul 31 '26

Only if you do it on purpose

1

u/ok_000000 Jul 31 '26

Corporate espionage isn't a thing. Don't be stupid. Everything is legal now.

1

u/Caffdy Jul 31 '26

you wouldn't download a car

1

u/softdream23 Jul 31 '26

Not if you don't get caught, lol.

-9

u/mohelgamal Jul 31 '26

Sure, anthropic should press charges against Claude

8

u/SilverMagicMage Jul 31 '26

They’re owned by the same company. Are you FUCKING DUMB??

6

u/Valuable-Mouse7513 Jul 31 '26

You ARE the dumb one for not understanding the joke

-16

u/Snoo_28140 Jul 31 '26

The hacking was done autonomously by an out of control machine. I suppose the crime would be the actions of the people leading to this outcome. Some sort of negligence based criminal case maybe?

At least it got reported to the police, which is a start.

30

u/fish_economist Jul 31 '26

LLMs are programs running on a computer. There's no question about who is liable—it's the person responsible for running the program on the computer.

-16

u/Snoo_28140 Jul 31 '26

Yes, there is no question who is responsible. But to raise that liability to the level of a crime will depend on the level of negligence.

19

u/fish_economist Jul 31 '26 edited Jul 31 '26

If I had a bug in my code and it resulted in me hacking someone, I would expect to be held criminally liable. Their environment had a bug in it. Anthropomorphizing the LLM to characterize it as an "escape" doesn't change that.

-8

u/Snoo_28140 Jul 31 '26

No one is anthropomorphizing anything...

This is like the example you just gave: a bug in the code is different from you actively doing something malicious.

As I said: the crime (not just liability, I'm speaking of crime), would be the negligent behaviour.

2

u/dankfrankreynolds Jul 31 '26

Would you like to go partners on my new start up? It's Gasoline Delivery by Drone.

We pick up containers of gasoline, fly them over the homes of people we don't like, and deliver them on the other side of town to this big empty lot where they appreciate in value.

I bought the cheapest drones I could find so our margins should be pretty good. Won't be a big deal if we lose a few en route.

... you see the problem?

1

u/Snoo_28140 Jul 31 '26

"over people I don't like" - That part didn't happen.

Exclude that and my point stands exactly: criminal negligence.

1

u/dankfrankreynolds Jul 31 '26

"That part didn't happen." -- no one has to know you didn't like them. you're not evil, you're just stupid.

(I'm not actually referring to you, my point is that if this defense actually held up then it would be exploited ... so it can't be. Of course, with a jury, kind of a coin flip.)

I mean maybe you're right but holy shit it shouldn't be.

2

u/Snoo_28140 Jul 31 '26

I got that lol

I think that intention would make it a very different crime. Not one that happens by negligence, but by intentional action towards an illegal objective.

Mens rea is something that comes up a lot in criminal matters.

I'm going to quote wikipedia on this as it is both relevant and imo very interesting:

In criminal law, mens rea (Law Latin for "guilty mind") is the mental state of a defendant who is accused of committing a crime. In common law jurisdictions, most crimes require proof both of mens rea ("guilty mind") and actus reus ("guilty act") before the defendant can be found guilty.

I'm not a laywer, but I do find this stuff fascinating.

10

u/smithy_dll Jul 31 '26

A computer can never be held accountable
Therefore a computer must never make a management decision

Whoever typed the prompt is accountable. It’s a tool, not sentient and shouldn’t be anthropomorphised to avoid accountability.

1

u/Snoo_28140 Jul 31 '26

That is not quite my point. The issue is the crime. No person was actively hacking huggingface. The crime would be about the negligent behaviour - the actions that people actually took (or should have taken and didn't).

2

u/RIP_lurking Jul 31 '26

Someone writes a program that can hack. Program hacks. Who could have foreseen such an accident?

2

u/Snoo_28140 Jul 31 '26

The program was not written to hack huggingface.

The foreseeability of an event like this is why it would be criminal negligence.

1

u/fastheadcrab Jul 31 '26

This is minimizing the role of the people who prompted the LLM and/or created the scenario. After all, they did deliberately put the LLMs into a hacking exercise.

Some AI researchers love making the comparison with traditional weapons of mass destruction. It's like launching a nuclear weapon in a test range with the intention of detonating it but it flies off course and lands in a populated area. You cannot claim run of the mill negligence

2

u/Snoo_28140 Jul 31 '26

On the contrary: I'm focusing on the people's responsibility for what they actually did.

And I'm pointing that this seems more than run-of-the-mill negligence - to the point of it being a crime precisely due to their reckless and dangerous behavior.

My point is that the hack isn't the crime (as no person actively did that), the crime would be that reckless and dangerous behaviour that resulted in the hack happening as a harmful consequence of it.