Simon Willison
Close
Quoting Thomas Ptacek
July 22, 2026, 7:59 PM
I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.
— Thomas Ptacek, doesn't think this even needs a frontier model
Tags: thomas-ptacek, openai, security, generative-ai, ai-security-research, ai, llms, sandboxing