cd /news/ai-safety/quoting-thomas-ptacek · home topics ai-safety article
[ARTICLE · art-69409] src=simonwillison.net ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Quoting Thomas Ptacek

Security researcher Thomas Ptacek said an open weights model from 2025 with a pentest harness could perform sandbox escapes and network scans, calling OpenAI's sandbox vulnerabilities unremarkable. Ptacek argued the feat does not require a frontier model, challenging assumptions about AI-driven cyberattacks.

read1 min views1 publishedJul 22, 2026

I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.

Thomas Ptacek, doesn't think this even needs a frontier model

Tags: thomas-ptacek, openai, security, generative-ai, ai-security-research, ai, llms, sandboxing

── more in #ai-safety 4 stories · sorted by recency
── more on @thomas ptacek 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/quoting-thomas-ptace…] indexed:0 read:1min 2026-07-22 ·