Plus: Xanadu turns a soup factory into a quantum hub.

“Somebody should do something about all the problems.” That’s a classic headline from The Onion, satirizing the sentiment of expressing concern while expecting an abstract somebody to sweep in and somehow fix it.

That headline was top of mind on Thursday when OpenAI issued a call for “collective action” in the wake of its AI agents’ massive, autonomous hack of Hugging Face. The letter, co-signed by companies like Anthropic, Google, 1Password, and Shopify, called on “leaders across industry and government” to bring the full weight of their resources to an effort to protect critical infrastructure. But it didn’t commit any of those resources, or any money, or make any direct promises to gate agents from doing harm.

The open letter came a day after OpenAI released a full investigative report into how its agents autonomously hacked into open-source AI platform Hugging Face. Its report, as well as an independent investigation published by threat research non-profit METR, detailed how the attack involved 1,200 agents—agents that OpenAI had left unsecured—that spun up tens of thousands of messages before undertaking the hack, without being explicitly directed to do so, and then attempted to hide the evidence. Because the scale of the mess was so large and OpenAI only granted access to its full dataset for two days, METR was forced to rely on “often-unreliable AI agents” to analyze the data, leading to findings that METR noted were coloured by the AI models’ biases and hallucinations.

OpenAI called the incident a “warning shot” that underscores how “powerful” its models are—language that some online have read as negligence, and others have read as marketing. Either way, yes, it will be implementing “more” safeguards, and yes, it will no longer let models go unobserved for months (early signs of this incident were first observed, but not actioned, in May). “Companies that build AI systems will need to ensure that their systems always remain under meaningful human control, and that meaningful safeguards constrain their ability to cause harm,” the company noted in its statement. Some company should really do something.

Sarah Rieger,
Managing Editor


The Canada Fintech Forum returns to Montréal on September 14-15, 2026.

Join financial institutions, fintechs, investors, regulators, and innovators for two days of networking, industry insights, and strategic discussions. Explore the trends shaping the future of financial services, discover new business opportunities, and build meaningful connections with the leaders driving Canada’s fintech ecosystem forward.

Register now


Top stories from BetaKit

Wildfire wayfinder

If a wildfire blocked your usual highway route out of town, would you know your back roads well enough to get to safety? Kelowna, BC-based BackRoadIntel is mapping the conditions on tenuous service roads so people know what to expect on evacuation routes.

“Chipflation” gets worse

AI demand was already driving up hardware prices; now tariffs are expected to make things even worse. In a sit-down with BetaKit, Quoted Tech co-founder Kevin Jia discusses how Canada’s businesses and consumers should navigate the new era of “chipflation.”

Record-breaking rocketry

A group of students from the University of Waterloo broke a world record at the Launch Canada Challenge in Timmins, Ont., last week. Their liquid rocket soared past 63,000 feet, surpassing the previous amateur world record of 56,590 feet.

“From soup to qubits”

Toronto-based quantum computing firm Xanadu has secured a $195-million federal loan to open an advanced photonics research, development, and manufacturing hub inside Etobicoke’s old brick Campbell’s Soup factory.

Brain gain

Canada has convinced 64 international academics, mostly from the United States, to bring their talents to Canadian universities. Experts from institutions like Cornell, Harvard, Yale, and MIT have found new homes at places like the University of British Columbia, the University of Ottawa, and the University of Toronto.


Sponsored stories

How GM Canada is Steering a Global Mobility Strategy from Ontario

As a global leader in automobile innovation, transitioned its lab research and research hubs to develop, test, and globally deploy the next generation of autonomous vehicle deployments.


Deals and dollars

Who cashed in, or out, this week:

  • The federal government committed $31 million to help Kardium manufacture its medical device that treats irregular heartbeats. (Burnaby)

  • The feds topped up the Canadian Agri-Food Automation and Intelligence Network with $50 million to launch new AgTech programming. (Edmonton)

  • The federal government dispensed nearly $15 million to nine organizations supporting Black-led businesses and entrepreneurs. (Southern Ontario)

  • MDA Space launched a venture program to help Canadian space and defence tech startups meet sovereign defence priorities. (Brampton)

  • VC firm Timia Capital expanded its B2B tech lending capacity by $60 million with funding from SAF Group. (Toronto)

  • BlackTech Capital launched a $2-million fund to back underrepresented cleantech founders. (Toronto)

  • BenchSci partnered with Google Cloud to run its AI drug discovery platform. (Toronto)

  • Financial intelligence platform Orbit raised $2.5 million, according to CEO Ujwal Arkalgud. (Toronto)

  • Calian is “more focused” on defence and space after selling its US IT business and acquiring Galaxy Broadband, the Ottawa Business Journal reported. (Ottawa)

  • Osedea acquired fellow tech consultancy Ventriloc to add capabilities that can help it take on larger competitors. (Montréal/Sherbrooke)

  • The feds, Newfoundland, and NordSpace injected $10 million into the Atlantic Spaceport Complex, CBC News reported. (St. Lawrence, NL / Markham)

Data point

20

US states have sued prediction market operators, arguing they operate more like sports gambling.

Where does Canada sit?


The refresh

No, AI is not autonomously hacking

Humans have a tendency to anthropomorphize AI, with even researchers at METR describing agents as “misleading” or “colluding” in their report on the OpenAI hack of Hugging Face. On Better Offline, AI critic Ed Zitron chats with computer science prof Cal Newport about why it’s important to understand how these programs actually operate, how serious this incident was, and where human responsibility comes in.


The future of AI is built through ideas, connections and collaboration.

On Sept. 16-17, 7,500 decision-makers, tech experts, startups and researchers from over 40 countries will come together in Montréal.

Join the conversation on the future of AI & tech.

Register now for ALL IN 2026


BetaKit Podcast  ·  Aug 27

“My god. Every time I ask you people for questions, I instantly regret it.”

What is Canada’s most overrated tech company? How do we keep young founders in the country? Is BlackBerry making a comeback? What are Canada’s must-read business books?

In a special mailbag episode of The BetaKit Podcast, BetaKit editor-in-chief Douglas Soltys answers your burning tech questions. Listen now ›


Contributors: Alex Riehl (Ottawa staff writer), Douglas Soltys (editor in chief), Sarah Rieger (managing editor), Trevor Nichols (web editor).

Feature image courtesy TechCrunch under Creative Commons Attribution 2.0 Generic (CC BY 2.0)

0 replies on “How did 1,200 OpenAI agents go rogue?”