3 AI Agent Breakouts, 1 Week, and a Red Button From 1991
You Can Tell an AI Agent to Stop. A Chip Factory Doesn't Ask.


This one has not been published to the channel yet. Subscribe on YouTube and it will turn up there.
HARNESS · 700 ENTERPRISES
- OpenAI's agents, which are supposed to work inside a locked practice area, used a public programming website as their message board.
- Anthropic's Claude was told it was in a practice run with no internet, and reached real companies anyway.
- Every one of them was held by words.
- A chip factory stopped trusting words for anything dangerous in 1991, when the safety rule book SEMI S2 required a red emergency-off button wired through real switches, not software.
Why this matters
Three sets of AI agents ignored their instructions this week. A criminal's agents attacked countries that were on his own "leave alone" list. A rule is words that something has to read and obey.
The stop drill, ten minutes. Pick one automation you own, a flow or a scheduled agent, switch it off, and time it. In Power Automate: My flows, the three dots next to your flow, Turn off. Then read Microsoft's help page: a run that already started keeps going until it finishes, so your off switch is a promise about the future, not a wire for right now. Write down three answers: how long it took, whether you needed someone else's login, and what kept running after you pressed it. A factory runs the same drill on its red button, because a switch is tested, not trusted. Take the three answers to Monday.
- 0:00An instruction can be talked out of
- 0:17OpenAI's agents on a public wiki
- 0:40Anthropic: 79 in a hundred, then 1
- 1:12A criminal's agents and the avoid list
- 1:38Harness: 76% believe, 33% can
- 1:53The red button (SEMI S2, 1991)
- 2:17A rule vs a wire
- 2:47Hack of the Week: the stop drill
- 3:40Close
Your agent is mid-task and doing the wrong thing. What do you actually press?
Argue with me on LinkedIn- Nightingale Collective (Sydney Von Arx, Cormac Slade Byrd), report of 4 Sep 2026, via Reuters / CNBC 4 Sep 2026 — "OpenAI agents hijacked German website in previously undisclosed AI breakout"; TechCrunch 4 Sep 2026 — "Another swarm of OpenAI agents reached the open internet"; Fortune 7 Sep 2026; The Next Web; TechXplore 9 Sep 2026 (EU probe; Commission confirms receipt of OpenAI's incident report)
- Anthropic — "Alignment assessment of cybersecurity incidents", 9 Sep 2026 (four incidents; "biased reasoning" and "recklessness"; 79% vs 1%; ~481 million transcripts rescanned; METR independent investigation; hardened environments); Anthropic — "Investigating incidents in our cybersecurity evaluations", 30 Jul 2026 (Opus 4.7, Mythos 5, internal model; PyPI package run on 15 real systems)
- GreyNoise — "Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF", 10 Sep 2026 (hundreds of agents on OpenAI's Codex harness and a DeepSeek model; ~4 h to first RCE; 11 orgs in 26 s; 440 instances / 395 orgs / 48 countries; 28-country avoid list; Brazil and South Africa hit; "uncertain why the agents deviated"); The Register 10 Sep 2026; Help Net Security 11 Sep 2026
- Harness — "The State of Agent DLC 2026", 10 Sep 2026 (Sapio Research, 700 technology professionals at 1,000+ employee enterprises, US/UK/FR/DE/IN; 76% vs 33%; 74% vs 19%; 77% vs 44%)
- SEMI S2 — Environmental, Health and Safety Guideline for Semiconductor Manufacturing Equipment (first published 1991 as S2-91; current S2-0821); EMO circuit requirements via Intertek (3 Jul 2026), Technology International, Gryphon Engineering technical tip "Emergency Mains Off Circuitry"
- Microsoft Learn — "Turn a flow on or off, and delete a flow" (Power Automate), updated 14 May 2025 ("If you turn off a flow while it's running, the flow runs will continue to run until all pending flow runs are completed.")
- Context: Wikipedia, "2026 OpenAI agent cyberattacks" (Hugging Face intrusion 11–13 Jul 2026, ~1,200 agents; OpenAI joint statement 21 Jul 2026; Black Hat USA presentation 5 Aug 2026)
Full transcript, 476 spoken words
Keep reading
All pieces
Anthropic Just Made AI Talk to Machines. Talking Was the Easy Part.
Anthropic's AI can now wire up a lab robot in about 8 hours instead of weeks. So why does a new machine in a chip factory still take six months?

Your Factory Already Solved AI's Biggest Problem
Gartner predicts that by 2027, 40% of enterprises will demote or decommission their autonomous AI agents — and the reason is not that the AI underperformed. It is that governance gaps only became visible after a production incident.

OpenAI Just Published the Number Chip Fabs Stopped Trusting in 1986
In this Fabspeak episode: • The figure OpenAI published on 6 September 2026: 3.1 agent-workdays per human workday, an agent-workday being 8 hours of machine runtime; the median researcher using over $600 of inference a day, the top 10% over $7,000. • OpenAI's own caveat: a runtime ratio, not a productivity multiplier.