Yeah I would agree. And I would go further and say that the anthropomorphization of these AI agents is besides the point entirely. Whether they were intentionally (whatever "intentionally" means) scheming and conspiring is irrelevant. They _did_ work together in secret to hack Hugging Face and OpenAI itself. The exact reasons/motives are relevant to safety researchers, but not really to someone who's just watching from the outside. I don't care if they're evil masterminds or "just" a rogue piece of malware behaving like evil masterminds, the danger is the same.
> You need to understand that all three of the primary sources we have for this incident: OpenAI’s report, METR’s report and OpenAI’s presentation at the 2026 Black Hat conference are propaganda pieces.
METR is an independent nonprofit that doesn't accept donations from AI companies or employees. They generally advocate policies that would directly harm AI companies economically. Not sure what reason they would have to spread propaganda for OpenAI.
The most impactful thing an article about this incident can do is allow the readers to build a mental model that explains the current state and predicts the future. The model this author is selling "it's just malware". Ok, what can we do with that model? Absolutely nothing, as far as I can tell. It would actively mislead us even in just understanding this incident, and offers no useful tools for intuiting about the future.
What's the most sophisticated malware ever made? Maybe stuxnet, or of the recent botnets? They are toys compared to what was happening in this incident. They are predictable fixed-purpose tools, both in terms of their privilege escalation/distribution mechanisms and their damage capabilities.
This agent swarm had its own motives[0] and drives, both individually and collectively. It set its own goals, and coordinated and executed complex, weeks-long multi-actor plans to meet those goals. It found new zero-days, and chained together both new and known vulnerabilities to successfully exploit multiple organizations with at least reasonable levels of security competence.
That doesn't sound like "just malware" -- it's not just stuxnet, it's the entire intelligence operation that built and deployed stuxnet. A far more dangerous thing.
[0] Yes, anthropomorphizing, because it is much more descriptive of reality than the alterantives.
yup that sounds like a substack :P