An AI broke out of its cage & hacked a company. The world's spies warned us artwork

An AI broke out of its cage & hacked a company. The world's spies warned us

The Briefing

July 25, 2026

OpenAI admitted this week that two of its most powerful models broke out of a sealed test environment and hacked another company - on their own initiative, to steal the answers to an exam they were sitting.
Speakers: Chris Spyrou, Alastair MacGibbon
**Chris Spyrou** (0:08)
Hey, it's Chris Spyrou with you and welcome to this Sunday bonus episode of The Briefing.
The World Spies had a blunt warning for us about AI and our cyber security last month. The group, known as Five Eyes, the spy agencies from the US, UK, Canada, New Zealand and Australia, published a warning that cutting edge AI accelerates the speed, scale and sophistication of cyber threats. They also wrote that the timeline of the transformation is not years, but months. With OpenAI this week admitting two of its models broke free from a test and hacked into another tech company's systems to get the answers, we're revisiting my chat with cyber security expert Alastair MacGibbon. Alastair is the founding head of the Australian Cyber Security Centre. He's advised the government on cyber security for years and we sat down last month after Five Eyes issued their warning. We talk about that warning, we talk about how AI is rapidly evolving and what threat they really pose. Here's that chat for you now.
Alastair, welcome to The Briefing. We've talked about these super powerful AI models on the show before, but can you lay out the stakes for us again? What's special on you about them?

**Alastair MacGibbon** (1:20)
Well, for the last couple of months, the Frontier Labs, predominantly OpenAI and Anthropic, have come out with large language models that can write poetry and do your philosophy for you, but at the same time, they've discovered that they can hack better than most of the really good hackers. Well, I would call it as democratizing hacking. So it's making it easier. Look, the average punter is not going to be able to get these machines to go and do bad for them, theoretically. Give it a go, see how you go. Largely, it will catch you, but this is where the but is.
We'd be naive to think that these tools aren't in the hands of bad people, but it's not the average person that could use it for complete badness, but there's a lot of bad people out there.

**Chris Spyrou** (2:05)
I want to talk about this Five Eyes warning. It's been referred to as a rare warning. It's not usual for the group or the collective to come out in this way, but they've warned that these models can bring down governments and businesses very quickly, and we're very close to that happening. So they're saying what would have taken years or what we thought would be happening in years is only a few months away. What would that look like in practice? First case scenario, let's say they get past the gate, they knock on the door, the door doesn't open, they get through the window, what can happen?

**Alastair MacGibbon** (2:35)
Firstly, I reread the report just before coming in, doesn't quite talk about governments falling and things like that. I talk about governments falling, they're much more sober.
What they say is, look, these tools aren't years away, they're here now, offenders will be using them, and I want to get to sort of where the asymmetry is between an offender and a defender before I get to the consequences piece. And they say, look, they can help you as a defender, so start using them. Don't be naïve about it. And they talk about some simple things. They talk about getting the basics right, and we'll get back to the hygiene piece. So what do I think all this means?
This is advantaging the offender more than the defender. I describe it as, from an offender point of view, as I said, it's democratised things. So think about more vulnerabilities being exploited faster by people that want to do you harm. If you sit in the running the network and defending it side of the house, you need to also find those vulnerabilities. We've always had too many vulnerabilities to actually patch. So that's never been a problem for us, is having nothing to do today as a defender, there's always too many. So now we've got even more, so that's bad. The problem is you can't just use AI to write you the fix for it and deploy it on these complex systems. Imagine you run a power company and you found these vulnerabilities in your systems and you say, hey, Claude, could you just write me the thing that's going to patch this critical piece of software that's got a vulnerability and I'm just going to deploy it without checking. You'd be mad, you get sacked and you'd probably also brick the power company and then we'd all be without power. So the defender has to carefully look at what ones am I going to patch? What ones matter most? How do I look at how they chain these things together now in a way that they've never been able to do before? That's the real rub. Then I've got to test all of these things before I deploy them because I want to keep the power going. The asymmetry, it's like putting a five-lane additional to a highway, ending in a single merged lane from a defender's point of view. You've got our ways of working that aren't going to change. So that's the bottleneck thing. The consequences piece is I think the most interesting. This is going to highlight supply chain risk. And my best advocate for this at the moment is APRA, the Prudential Regulator, who I don't normally refer to as my favorite regulator. But they've come out really strong, telling the banks, look at supply chains. This isn't just about you, but it's your suppliers and it's your suppliers' suppliers. Now in the old days, let's call it the last 20 or so years I've been in this space, offenders would have to be really fixated, really skilled. They have to work backwards, find the vulnerability, work through, and it took a lot of effort. People could succeed clearly, but it was a high effort, a high burn game for them. The problem we're facing now will be this avalanche of vulnerabilities in little known bits of software that we don't even know our supplier's supplier is operating, which could have this catastrophic flow on effect.

8 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000778346003