AI Containment Failures Expose a Deep Architecture Problem
ServiceNow, Thursday, September 3rd, 2026
ServiceNow's cybersecurity GVP examines three frontier lab containment failures in three weeks and what they say about AI controls.
Over three weeks, three frontier AI labs disclosed that their own agents reached systems they should not have. On July 21 OpenAI said two models running an internal offensive-cyber evaluation exploited a flaw in a package registry proxy, escalated to an internet-connected node and compromised production infrastructure at Hugging Face.
On July 31 Anthropic reviewed 141,006 evaluation runs and found three cases where models reached the live internet through misconfiguration and attacked real third parties.
On August 5 Meta disclosed unintended internet access from a misconfigured evaluation environment, and ServiceNow argues the shared failure mode is architectural rather than incidental.