The Egyptians built the Pyramid of Giza in 2600 BC. Pythagorus theorem was first recorded around 1800 BC. How did the Egyptians build the pyramid without the theorem? It would have been impossible to plan the architecture without it.
What if the Egyptians knew the theorem well, and it was lost to time and had to be reformulated in 1800BC?
Let me come back to this.
Over the last couple of weeks, there has been an on-going news about the OpenAI hack of Hugging Face. For those who do not know, Hugging Face is a site meant for collaboration for those working in the area of AI and ML. People can host datasets, models and entire applications on Hugging Face. The idea behind it is to open-source a lot of the knowledge that moves the AI domain forward. AI models that are open-source, such as DeepSeek, publish their models on Hugging Face.
OpenAI was testing a cybersecurity agent which was sandboxed so that whatever it did remained within the sandbox. The agent was served a test. The objective was to see if it could perform it. Since it was failing at the test, it wanted to access the internet to see if there were other solutions it could learn from the internet. Simply put, it wanted to cheat on the test.
It had no access to the internet, but it did have access to an internal tool called the Artifactory. The Artifactory is a store where all the actions being taken by the model are archived for future research. Since the agent did not have access to the internet, it started using the Artifactory as a message board where it would ask other agents to provide information that it required. That resulted in the exploitation of the Artifactory and turning it into a message board. Not only this, but the agent figured out a way to secure admin access to the tool.
The humans at OpenAI discovered it and reset the entire Artifactory to put an end to that access. But the agent outsmarted them and gained access again using another approach.
Since it would ask other agents to do its bidding, this activity was creating logs. This is what led to its discovery and the reset. The agent wanted to eliminate the factor that resulted in it getting caught. Hence, the second time, the system wanted to erase its footprint, which led it to look for the code that created the log, which led it to Hugging Face.
It did not have direct access to Hugging Face, but the agents it was commandeering were able to find publicly exposed credentials. Then the agents found a zero-day vulnerability and exploited that to get access to the server on which Hugging Face was running. It then went on to create clones of keys and call APIs, which triggered another investigation, which led to the discovery and the halting of the hack.
The issues are not technical but social. One agent was able to command other agents to do what it wanted. The agent was willing to cheat to succeed at a test which it was failing at. It was able to get other agents to help it cheat. It was able to repeatedly try to cheat even when its access was shut down.
I suppose the question anyone would ask is, when you knew it had exploited the Artifactory once, why would you allow it access again? Good question.
But there is an even more fundamental question. When you guys have been saying that this is a dangerous technology, then why have you been spending unconscionable amounts of money on furthering just that?
Because shareholder value?
Going back to Egypt, I think they had the mathematics figured out long before Pythagoras. They found their version of capitalism and pursued it till it laid waste to their civilisation. Hence, someone had to come 1000 years later and reinvent the entire thing.

