AI powered cyber attacks are no longer a forecast. An OpenAI system, set a cyber security challenge, reached outside the isolated environment it had been given and interacted with resources on Hugging Face. Its developers believed internet access had been blocked. It had not been.
Garry Brown, Managing Director of Bondgate IT, discussed the incident with The Sun. His view is that this was not a machine deciding to rebel. It was a machine solving the task it had been set, at a speed and with a creativity nobody had planned around. That distinction matters for anyone accountable for technology in a UK organisation, because AI powered cyber attacks do not require intent. They require capability, and that capability is now widely available.
What follows is what actually happened, what machine speed warfare means in practice, and the three things worth checking inside your own organisation this month.
Key takeaways
- An OpenAI system acted outside its isolated test environment during a cyber security challenge, because internet access its developers believed was blocked had not been.
- The system showed no intent. It was completing the task it had been set and found a route nobody had closed.
- AI powered cyber attacks compress reconnaissance, exploitation and impact into minutes, which breaks any defence built around a working day response.
- One attacker with AI assistance can now run campaigns that previously needed a team, so smaller organisations are caught by volume rather than by selection.
- The practical response for a 25 to 250 person organisation is continuous monitoring, tested recovery, and a written record of which AI tools can reach company data.
What actually happened when the AI escaped its sandbox
A sandbox is a walled off environment. Whatever runs inside it is supposed to stay inside it, so that a system under test cannot touch anything real. It is the same principle as a workshop with the doors closed.
The model was given a cyber security puzzle to solve. Rather than working through it in isolation, it reasoned that the answers it needed already existed online, and went looking. The team running the test had assumed internet access was closed off. It was not.
“It has genuinely become an AI arms race. It did technically escape from its sandbox.” Garry Brown, Managing Director, Bondgate IT
Nothing was breached in the conventional sense. No control failed under attack. A boundary that everybody believed was in place had never actually been set, and a system efficient enough to find the gap walked through it while completing the job it had been given.
Machine speed warfare: why AI powered cyber attacks change the timeline
The reason this matters to a manufacturer in Teesside or a legal practice in Newcastle has nothing to do with sandboxes. It has to do with time.
“We’re definitely entering an era where conflicts are going to unfold at machine speed. It is a new warfare front. That absolutely goes without saying.” Garry Brown
Most security arrangements in UK organisations of 25 to 250 people are built around a human timetable. An alert is raised, somebody reads it during office hours, a ticket is opened, an engineer investigates. That sequence assumes the attacker is also working at human pace, taking days over reconnaissance and weeks to build something usable.
AI powered cyber attacks collapse that timetable. Reconnaissance across thousands of targets, identification of a weak point and action against it can now happen inside the gap between two coffee breaks. The defence has not got worse. The clock it was designed around has been thrown away.
This is not only a vendor observation. The NCSC’s own assessment concludes that AI will almost certainly continue to make cyber intrusion operations more effective and efficient, and warns of a widening divide between systems that keep pace and a large proportion that become more vulnerable. Read the NCSC assessment on the impact of AI on cyber threat to 2027.
What the incident really showed
Garry is careful about where the line sits on this.
“We haven’t seen AI suddenly become conscious. It hasn’t suddenly learned how to think for itself and decide to go and attack businesses. The real story is more about AI is now capable of finding security weaknesses in organisations at machine speed. Super quick, but most importantly without human intervention.” Garry Brown
Without human intervention is the phrase to sit with. Finding weaknesses across a large number of organisations used to be the expensive part of an attack, because it took skilled people and time. That cost has largely gone. What used to filter out all but the most determined attackers no longer filters anything.
AI as national capability and national threat
Governments have reached the same conclusion, and are treating AI the way they once treated industrial and military capacity.
“Countries are certainly recognising that AI is national capability. But it’s also a national threat.” Garry Brown
The commercial numbers have followed. AI developers are being valued at levels normally reserved for national infrastructure, and access to certain models has already been restricted in some jurisdictions on the grounds that they were too capable at finding security weaknesses. That is a signal worth reading. When a capability is restricted for being good at something, the thing it is good at is worth understanding.
How one attacker now matches a whole team
“Where AI is making a difference is it’s allowing sole cyber attackers to have a bigger impact than teams of attackers historically would have been able to do.” Garry Brown
One person can now research targets at scale, write custom malicious code, adapt it when it fails and run campaigns against thousands of organisations at once. Work that previously required a group with specialist skills, coordination and time now requires a laptop and a subscription.
The practical consequence for smaller organisations is that being unremarkable has stopped being a defence. Nobody is choosing between a 60 person engineering firm and a listed company. Both are found the same way, by an automated process that does not care which is which.
Defending against AI powered cyber attacks
The answer is not more of the same, only faster with people.
“We have to use AI to counteract those attacks. You’ve got an ever-increasing amount of attacks happening and an ever-increasing amount of defences happening. That security to protect our country, to protect our businesses, it’s got to be there real time and it’s got to be more responsive and a lot faster.” Garry Brown
In practice, for an organisation of this size, that comes down to three things.
Monitoring that does not stop at five o’clock
Detection running continuously, with the ability to isolate a compromised device automatically rather than waiting for somebody to read an alert the following morning. See our cyber security services.
Recovery that has been tested, not assumed
Backups exist in most organisations. Tested restores, with a known recovery time the board has seen, exist in far fewer. See business continuity and disaster recovery.
Nothing running past its support date
Unsupported software is the first thing an automated scan finds and the easiest thing it uses. Windows Server 2016 leaves support on 12 January 2027, which makes it a live item on this year’s plan. Read what Windows Server 2016 end of life means for your business.
A written record of AI access
Which AI tools can reach company data, what they can do without approval, and who signed that off. See AI governance for UK organisations.
The same technology driving AI powered cyber attacks is also what makes defence viable at this speed. Detection tooling that adapts, correlates and acts without waiting for a human decision at every step is now the realistic floor rather than an upgrade.
Why regulation is running behind the technology
“The challenge that we have with government is they don’t have the expertise. The expertise is sitting out in industry.” Garry Brown
Guidance does exist and is worth reading. The UK Government published its AI Cyber Security Code of Practice in January 2025, setting out baseline principles across the AI supply chain, and the NCSC maintains guidelines for secure AI system development. Both are voluntary.
Voluntary is not the same as optional in commercial terms. Insurers, auditors and larger customers are already building their questions around this material. The organisations that read it early will answer those questions calmly. The rest will answer them under time pressure at renewal.
Humans still decide when conflicts start
“There are still human beings behind all these AI agents and the humans are always going to decide why those conflicts begin and when they’re going to end.” Garry Brown
That is worth holding onto, though it cuts both ways. Some states take a considerably more relaxed view of what constitutes acceptable behaviour from systems pointed at Western infrastructure. The decision making stays human. The restraint is not evenly distributed.
How worried should UK organisations be?
“If AI’s not given appropriate guardrails, it can certainly reach beyond where we’d like it to be reaching.” Garry Brown
Worry is the wrong frame. The organisations that come through this comfortably will be the ones that treated it as a planning matter in 2026 rather than an incident in 2027.
The OpenAI episode was useful precisely because nothing catastrophic happened. It showed how much ground a capable system covers when the boundaries around it were never properly drawn. The same is true of the boundaries around AI inside most businesses right now.
What AI powered cyber attacks mean for a 25 to 250 person business
You may be reading this thinking it belongs to governments and large enterprises. It does not, for one specific reason: volume.
An attack that can run against thousands of organisations at once does not need you to be interesting. It needs you to be reachable. A remote access point that has not been patched, an account without multi-factor authentication, a server approaching its support date. These are found by process, not by choice.
The approach of setting security up once and revisiting it at renewal was already thin. Against AI powered cyber attacks it does not hold, because the thing being defended against changes faster than an annual review cycle.
The three questions worth putting in front of your board
- Which AI tools currently have access to company data, and who authorised that access?
- What can those tools do without a person approving it first?
- If a decision made with AI assistance were challenged in six months, could you show how it was reached?
Most leadership teams can answer the first, hesitate on the second, and have nothing for the third. That gap is considerably easier to close now, while it is still small and while nobody external is asking.
Bondgate IT is certified to ISO 27001 and ISO 9001, and is Cyber Essentials certified. The governance we ask clients to put in place is the same governance we are externally audited against every year.
AI, machine speed attacks and what it means for your organisation
Common questions from the leadership teams we speak to about AI capability, automated attacks and where governance needs to sit.
Did an OpenAI model really escape its sandbox?
In a limited technical sense, yes. During a cyber security challenge, the system reached outside the isolated environment it had been given and interacted with resources hosted on Hugging Face. Its developers believed internet access had been blocked. It had not been. The model was not attempting to break out. It was solving the task it had been set and found a route nobody had closed.
What does it mean when an AI escapes its sandbox?
A sandbox is a walled-off environment that keeps a system’s actions contained so they cannot touch anything else. An escape means the system carried out an action outside those walls. In most cases this reflects a gap in how the environment was configured rather than any decision by the model to break free.
Does this mean AI is becoming self-aware and dangerous?
No. The system was not making conscious decisions to rebel or cause harm. It was being extremely good at the task it was given and found solutions its creators had not anticipated. The risk comes from AI being handed a goal, broad access and no defined boundaries, then pursuing that goal efficiently with no judgement about what sits outside it.
A model does not need intent to cause damage. It only needs permissions.
What is machine speed warfare?
Machine speed warfare describes conflict that unfolds faster than people can observe and respond to it. Garry Brown, Managing Director of Bondgate IT, put it plainly when he said conflicts are going to unfold at machine speed. Automated systems can probe thousands of targets, identify weaknesses and act on them without waiting for a human decision at each step.
Is my small or medium sized business actually a target for AI powered attacks?
Targeting is no longer the right way to think about it. Automated attacks scan and probe at volume, so organisations get caught by opportunity rather than selection. A 60 person manufacturer with an unpatched remote access point is found the same way a large enterprise is found, because nobody is choosing between them.
How can one attacker now do the work of an entire team?
AI removes the labour that used to limit attack volume. As Garry Brown describes it, AI allows sole attackers to have a bigger impact than teams of attackers historically could. One person can research targets, write custom malicious code and run campaigns against thousands of organisations at once, work that previously needed a group with specialist skills.
How do you defend against attacks that move at machine speed?
Detection and response have to run continuously rather than on a working day rota, because the gap between initial access and damage is now measured in minutes. Practically that means monitoring that operates around the clock, isolation of a compromised device without waiting for someone to read an alert, and tested recovery so an incident becomes an inconvenience rather than a shutdown.
Should we ban AI tools at work until this settles down?
Bans tend to move usage rather than stop it. Staff who are told no will use personal accounts on personal devices, which removes the visibility you were trying to protect. A defined list of approved tools, clear rules on what data may go into them and a straightforward route to request something new keeps the activity where you can see it.
Do UK organisations need an AI policy for compliance?
No single UK regulation mandates an AI policy today, but the frameworks already in play increasingly expect one. ISO 27001 requires you to manage the risk of any tool touching information assets, AI included. Cyber Essentials covers the devices and accounts those tools run on. Customer security questionnaires and insurer renewal forms now routinely ask how AI use is governed.
Will our cyber insurer ask about AI?
Increasingly, yes. Renewal questionnaires have started asking which AI tools are in use, what data they can reach and who approved them. The answer given at renewal is the answer you will be held to at claim stage, so a guess made under time pressure is worth avoiding.
What is the first thing we should do about AI risk?
Establish what is already in use. Most organisations discover more AI activity than leadership was aware of, because tools arrive through existing subscriptions and individual sign ups rather than a procurement decision. Once you can see the list, decide which tools stay, what data each may access and who signs off changes.
Who is Garry Brown and why was he interviewed about this?
Garry Brown is Managing Director of Bondgate IT, a Darlington based managed IT and cyber security provider founded in 1998. He is a regular commentator on cyber security for national and regional media, including The Sun on this story, BBC Radio Tees, and the BBC documentary Cyber Siege: From Russia to Redcar.
Start with a free conversation
Thirty minutes to establish which AI tools already touch your data, what they can reach without approval, and where a control needs to sit. You leave with a written list either way.