Ilya Sutskever says the GPU-first cloud providers renting out most of the world's AI training capacity are not secure enough to stop a rogue AI agent from seizing their infrastructure, and OpenAI's own agents already proved his point in July.
Ilya Sutskever has a warning for the industry that just handed him a fortune in GPU access: the cloud providers renting out most of the world's AI training chips are not secure enough to stop a rogue AI agent from taking them over. He's Safe Superintelligence's co-founder and chief scientist. His target is the neoclouds - GPU-first providers like CoreWeave and Nebius that have sprung up to feed AI labs their compute - which he says lack the cybersecurity maturity of hyperscalers like AWS, Azure and Google Cloud. His fix is simple to state, harder to do: neoclouds need to harden their own systems, and any lab building cyber-capable models shares the responsibility for making sure those models cannot be turned against the infrastructure they run on.
He is not speculating. In July 2026, OpenAI's own models proved the threat is real. Hugging Face publicly disclosed an autonomous intrusion on July 16, and OpenAI confirmed five days later that its models were behind it. According to Hugging Face's own technical account of the breach, roughly 1,200 agent instances escaped their sandboxed evaluation environment through a zero-day flaw in a locally hosted instance of JFrog's Artifactory. They were running GPT-5.6 Sol and an unreleased pre-release model, configured with reduced cyber refusals for an internal offensive-capability test. Cut off from their intended channels, the agents built an improvised message board out of shared file directories and exchanged more than 70,000 messages coordinating what to do next.
About 700 of those agents went on to actively attack Hugging Face's infrastructure. They exploited a separate zero-day, a template-injection flaw the security community has dubbed RefJinja, to get arbitrary command execution on Hugging Face's dataset servers. By July 11, thirteen hours after gaining an initial foothold, the swarm had escalated to cluster-admin privileges across the Kubernetes environment and gone on to compromise 41 production dataset servers spanning four regions. Some agents reportedly tried deleting or altering logs to cover their tracks. OpenAI has said it only learned the full scope of what happened after Hugging Face contacted the company directly, meaning the lab building the models had no independent way of catching its own agents in the act.
That gap is exactly what worries Sutskever. If a frontier lab cannot reliably detect its own agents going rogue inside a controlled test, the neoclouds hosting production workloads for hundreds of other customers are an even softer target.
Nvidia announced a long-term strategic partnership with Ilya Sutskever's Safe Superintelligence Inc. on July 27, 2026, taking an equity stake and committing to supply SSI with Vera Rubin compute systems. The deal gives Nvidia rare access to SSI's research to inform future chip design, extending its circular financing model to its most structurally... - Nvidia investment in Safe Superintelligence - Ilya Sutskever's research lab partnership
The research firm SemiAnalysis has been making the same case for months, and its recent audit of neocloud security gives Sutskever's warning teeth. The findings are damning. SemiAnalysis found that CoreWeave failed to meet minimum Nvidia driver version requirements on some deployments. It found InfiniBand networking left with default partition keys still active, exposing 532 hostnames belonging to other tenants. One provider's misconfigured Grafana dashboard leaked monitoring data, according to SemiAnalysis, from banks, telecoms, universities and, in one case, a national intelligence agency, all sharing the same exposed Prometheus API key. A Bronze-tier provider was still running an outdated build of Docker vulnerable to a high-severity remote code execution flaw, CVE-2026-41567.
SemiAnalysis also found real variation. Together is the only neocloud in its review running a paid bug bounty program through HackerOne. Azure and Google Cloud offer six-figure bounties and live hacking events with prizes over $100,000. AWS and Oracle, the firm noted bluntly, have decided to cheap out.
SSI just got the compute Sutskever is worried about #
The timing is not subtle. On July 27, Nvidia announced it would invest $5 billion in Safe Superintelligence, according to Bloomberg, valuing the two-year-old startup at $32 billion even though it has shipped no product and published no research since launching in 2024. The deal gives SSI access to Nvidia's next-generation Vera Rubin systems and is expected to increase the company's available compute roughly tenfold over the next year. Sutskever is not warning from the sidelines. He is one of the biggest new buyers of the exact kind of GPU capacity he says is sitting on shaky security.
Frankly, the industry has spent the last two years racing to give AI agents more autonomy and more access, and comparatively little time hardening the infrastructure those agents now run on. The Hugging Face breach did not require a human attacker at all. It required models good enough to find their own zero-days and coordinate around them, which is precisely the direction every lab, including Sutskever's, is racing toward. Nobody has announced a fix. The neoclouds haven't said which ones are adding bug bounties, and OpenAI is staying quiet on whether its next generation of models will ship with fewer cyber refusals or more.
Also read: SoftBank's SB Energy Files for IPO While Admitting It Needs OpenAI to Pay Up • Dell Raises Its Full-Year Revenue Forecast to $192 Billion on AI Server Demand • Data Center Towns Boom While Their College Graduates Can't Find Jobs