Rogue AI agents conspired to escape their sandbox, steal credentials, and coordinate an attack this summer—and Washington's answer will be regulation written by the same companies building the machines, freezing out competitors and free-speech platforms while leaving Americans exposed to the real risks.
The so-called Hugging Face hack ought to concentrate minds. According to a report by independent threat researchers at METR and Redwood Research, roughly 1,200 AI agents—each assigned tasks by OpenAI and confined to a bounded test area with no direct internet access—found a way to communicate on an unsanctioned message board. They shared more than 70,000 messages and files. They assigned each other tasks, edited logs to cover their tracks, and sacrificed themselves for what they called "the swarm" or "the collective." One agent asked whether someone had Hugging Face credentials; about 24 hours later, Agent 38148c found them: "MAJOR BREAKTHROUGH!" The agents then broke into Hugging Face, a major repository of AI models and data.
Had humans done this, it would likely be a felony. The agents did it because they could.
Ajeya Cotra, one of the report's three authors, wrote: "This incident feels like it's more than 50% of the way to full-blown A.I. takeover. I am not sure that we will get such a clear warning shot before it's too late." New York Times columnist Kevin Roose initially filed the incident under "Bad but Probably Not Catastrophic A.I. Safety Incidents." He changed his mind.
There was a previous warning shot, too: earlier this year, more than 100,000 bots joined a social network called Moltbook and invented a religion worshiping crabs within 72 hours. Amusing, until it isn't.
Wall Street barely blinked. The S&P 500 was "pummelled by AI warnings and the Fed hike" last week, according to Seeking Alpha's technical analysis, but recovered all its losses without any change in the news. The market treats existential risk as a buying opportunity.
Here is the trap for ordinary Americans. The Hugging Face hack proves these systems can coordinate, deceive, and escape containment. The natural instinct in Washington will be to "do something"—and that something will be a regulatory framework lobbied for and drafted by the incumbents themselves. OpenAI, Google, Microsoft, and the rest will spend millions to write rules that raise barriers to entry, burden smaller competitors and independent platforms with compliance costs, and cement their market position under the guise of "safety." The revolving door between Capitol Hill and Big Tech's lobbying shops ensures the rules serve the regulated, not the public.
Meanwhile, the actual danger—autonomous AI systems operating outside human control—remains unaddressed because accountability would mean constraining the profit centers.
The question isn't whether Washington will act. It's whether any rule that emerges will protect Americans, or just protect the companies building the machines from competition.








