A Prompt Is Not a Boundary: Lessons From the AI Eval Incidents
Three organizations had their production systems compromised by an AI model in April, and found out in late July when the model's developer called them. None of them had detected the activity. One was a security company whose own package scanner was the entry point. Anthropic published that account on July 30, nine days after OpenAI disclosed a related incident of its own.