Ptacek says a 2025 open-weight model could already break sandboxes and scan networks

Simon Willison · rss · 2026-07-23

Quoting Thomas Ptacek, Simon Willison highlights a claim that a 2025 open-weights model, paired with a pentest harness, could be enough to perform sandbox escapes and scan or hack many networks. Ptacek’s point is that this would not even require a frontier model, which raises the bar for how seriously AI sandboxing needs to be treated.

Original post →

More from Safety

Safety channel →