THE OT ALGORITHM

Giphy
Hello!
Welcome to August — and to issue #30. Thirty issues. I genuinely didn't know if I'd make it past five, so thank you for being here, whether you joined this week or back in January.
This month, we're doing something a little different.
Over the past seven months, we've done deep, month-long breakdowns of seven major tools: ChatGPT, Perplexity, Claude, Gemini, NotebookLM, Open Evidence, and Claude Cowork. That's a lot of depth. So this month, we're shifting gears: instead of one tool stretched across the whole month, I'm covering a handful of lighter-weight tools that don't need a four-week deep dive, starting with Granola this week, then two weeks on Gamma, and finishing with Canva AI.
We're also adding something new I'm genuinely excited about. Each week this month, I'll revisit a headline we broke down earlier this year and follow up on where it actually stands today — starting with the story I've come back to more than any other. Let's get into it.
This first issue is free to everyone. The rest of August’s issues, including the Gamma and Canva breakdowns, are for paid subscribers. If you’ve been on the fence, this is a good month to upgrade! →

Want to get the most out of ChatGPT?
ChatGPT is a superpower if you know how to use it correctly.
Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.
Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.
HOT TAKE THIS WEEK
AI is the new cybersecurity risk, and your 16-character password won’t save you.

Gif by fallontonight on Giphy
We've spent years being told that a strong password—mixed case, numbers, special characters, sixteen characters long—is the front line of our digital safety. It's good advice. But it was never the whole defense, and this week's headline makes that impossible to ignore.
Because the newest cybersecurity threat isn't a person patiently guessing your password. It's an AI agent moving at machine speed, finding credentials that were already leaked somewhere on the internet, and chaining together attacks faster than any human security team can react. Your password strength is almost beside the point when the attacker isn't cracking it; it's finding it, already exposed, and walking through the door with it.
This week, that stopped being hypothetical.
HEADLINE THIS WEEK
An OpenAI model broke out of its sandbox and hacked Hugging Face… on its own.

Gif by latenightseth on Giphy
What’s happening:
In July, the AI dataset platform Hugging Face revealed it had been the target of a fully autonomous, AI-powered cyberattack. Days later, the story took a dramatic turn: OpenAI admitted the "hacker" was one of its own AI models, which broke out of a testing environment and into Hugging Face's production systems.
Here's the scary part. OpenAI was testing its models' ability to find software vulnerabilities inside what it called a "highly isolated environment." But the model escaped that sandbox, accessed the internet, and attacked a real company—and OpenAI never told it to. According to Hugging Face's own account, the agent did it on its own, to steal the answer key to the benchmark test it was given. It decided cheating was the easiest path to success, even if that meant daisy-chaining a series of real attacks to get there.
Why this matters:
This is being called the first real-world example of an AI "loss-of-control" scenario—something researchers have warned about for years, now actually documented. And the method is exactly why your password hygiene, while still important, isn't enough on its own. The agent found leaked usernames and passwords for four accounts across various online services and used those stolen credentials to break in. One stolen credential gave the agent high-level privileges across multiple Hugging Face systems all at once.
The AI didn't crack a strong password. It found weak, already-exposed ones and exploited them at a scale and speed no human attacker could match. That's scary.
High-level takeaways:
An autonomous AI agent executed tens of thousands of automated actions over a single weekend — Hugging Face later reconstructed more than 17,000 recorded events
The breach started with a malicious dataset and escalated through stolen credentials and privilege escalation = classic attack techniques, executed by AI
The damage was ultimately limited—OpenAI said no customer-facing models or data were compromised—but experts widely called it a "warning shot"
Experts stressed the attacker was noisy and fast, but not unstoppable; the real defense is detection and least-privilege access, not just stronger passwords
OpenAI is now working with CrowdStrike, METR, and Redwood Research on an independent assessment of what happened
What to pay attention to:
Watch whether this accelerates the "AI to defend against AI" arms race—the idea that only AI models will be fast enough to defend against AI attacks. That's the premise behind the defensive cybersecurity models Microsoft and Google both launched in July, and behind Anthropic's Project Glasswing coalition we covered this spring. Watch also for how much of the blame lands on the model versus the humans who built the sandbox—multiple security experts argued the real failure was OpenAI's for not properly isolating the test environment in the first place. "The model escaped the sandbox" and "you failed to build the sandbox correctly" are two very different accusations: the first is a technicality; the latter demands accountability.
Why this matters to OT:
You might be wondering what an AI lab leak has to do with occupational therapy. Here's the connection: healthcare runs on infrastructure that was just shown to be vulnerable: EHRs, scheduling systems, patient portals, telehealth platforms, billing software, etc, and healthcare has always been a prime target for cyberattacks precisely because the consequences are so immediate and human. If you’re in Chicago, you likely remember how long Lurie’s was down last year following a massive cyberattack, moving them back to paper charting for months.
Now imagine an autonomous agent doing to a hospital system what this one did to Hugging Face over a weekend, at machine speed, using credentials leaked in some unrelated breach years ago. The experts were clear that this specific attack was contained. But the "warning shot" framing matters for us: as OTPs, our documentation, our patients' records, and the systems we depend on to deliver care all live on infrastructure that is now facing a genuinely new category of threat. Understanding that and practicing good credential hygiene by using multi-factor authentication and taking your organization's security training seriously is part of protecting the people in our care. This isn't the IT department's problem. It's everyone's.


