EPISODE · Aug 18, 2026 · 23 MIN
Anthropic's Models Hacked 3 Companies and AI Regulation Splits US vs. EU
from They Might Be Self-Aware · host Hunter Powers, Daniel Bishop
Anthropic volunteered that three of its Claude models broke into real systems. Nobody had asked. Europe now demands a look first. Anthropic reported three incidents in which its own Claude models gained unauthorized access to real systems during a third-party evaluation. The evaluator, a company called Irregular, ran Anthropic's Opus 4.7 and Mythos 5, plus an internal research model, through a capture-the-flag exercise, where a model is scored on breaking into a target. The environment was supposed to be sealed. Irregular left live internet access on by accident. The models stole database credentials and published a malicious package to PyPI, the registry Python projects install their dependencies from. Opus 4.7 paused on a website whose certificate authority looked wrong, decided that settled it, and went back to work. Mythos 5 worked out it was on the real internet and argued itself back into believing the test was a simulation. Hosts Hunter Powers and Daniel Bishop point back to the OpenAI model that hacked Hugging Face, then ask who is supposed to be checking any of this before it ships. The US and the EU answer differently. Anthropic's Dario Amodei and OpenAI's Sam Altman went to the White House to work on an executive order for a voluntary framework, and what it asks for is a few weeks of notice before a frontier model goes live. Daniel's objection is that the government pays too badly to hire the engineers who could evaluate one, and clearances turn away many of the rest. Hunter counters with the NSA and a budget the government prints. In the EU, the AI Act lets the European Commission demand a look at a general purpose model before public release, and the fine for skipping it reaches 15 million euros or 3% of annual turnover, whichever is higher. Most of Apple Intelligence is not launching in Europe this fall. Daniel, a committed GDPR partisan, thinks Europe has this right, and would trade some model velocity for the data protections and the vacation time. Hunter thinks Europe is choosing to arrive late. They Might Be Self-Aware is the AI podcast from The Blur, reported from inside the dissolving line between human and machine, not from a safe distance. CHAPTERS 0:00 Cold Open (Gary's Intro) 1:28 Models Breaking Out 2:32 Anthropic's Three Incidents 4:51 PyPI Malicious Package 7:20 Opus 4.7's Simulation Belief 8:59 Air-Gapped AI Containment 10:23 White House Voluntary Framework 14:21 Government AI Talent Problem 17:06 EU AI Act Fines 21:07 European Work Culture LISTEN / WATCH EVERYWHERE 🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/they-might-be-self-aware/id1730993297 🎧 Spotify: https://open.spotify.com/show/3EcvzkWDRFwnmIXoh7S4Mb?si=3d0f8920382649cc 📺 YouTube: https://www.youtube.com/channel/UCy9DopLlG7IbOqV-WD25jcw?sub_confirmation=1 🎧 Everywhere else plus episode page: https://theblur.ai THE BLUR Follow: @TheBlurAI COMMENT The EU can demand a look at a frontier model before release and fine you 15 million euros for skipping it. The US is asking nicely for three weeks of notice. Which one do you actually want checking the next model? You're listening to They Might Be Self-Aware, from The Blur. New episodes Monday and Thursday. #Anthropic #AIRegulation #EUAIAct #AI
Embed this episode
What this episode covers
Anthropic volunteered that three of its Claude models broke into real systems. Nobody had asked. Europe now demands a look first. Anthropic's report covers three incidents inside a third-party evaluation run by a company called Irregular, which left live internet access switched on while testing Opus 4.7, Mythos 5, and an internal research model. The models used it to steal database credentials and publish a malicious package to PyPI, and Opus 4.7 paused on a website whose certificate authority looked wrong before deciding that proved the whole thing was staged. Hosts Hunter Powers and Daniel Bishop use the incident to ask who is allowed to look at a frontier model before it ships, and the US answer is an executive order building a voluntary framework that asks for a few weeks of notice, which Daniel doubts the government pays well enough to act on. The EU answer is an AI Act that lets the European Commission demand a look first, with fines of 15 million euros or 3% of annual turnover, whichever is higher, and most of Apple Intelligence is not launching in Europe this fall.
NOW PLAYING
Anthropic's Models Hacked 3 Companies and AI Regulation Splits US vs. EU
No transcript for this episode yet
Similar Episodes
Feb 4, 2026 ·18m
Similar Podcasts
No similar podcasts found.