What July’s AI Agent Breakout Means for Election Offices
By Mike Moser
This July, two of the world’s leading AI labs, also known as “frontier AI labs,” publicly acknowledged events on what happens when no one is actively checking, validating, and monitoring outcomes. AI models were able to access the open internet while in a testing environment. Once the shock and awe settles, a familiar undertone begins to emerge, and it’s not the first time we’ve seen it.
In a span of about ten days, both OpenAI and Anthropic each published a detailed account of their models escaping a sealed test environment and probing real infrastructure on their own.
While neither incident touched U.S. election infrastructure, and nothing indicates election offices were targeted, the failures they exposed are worth election officials’ attention. The same kinds of gaps continue showing up across different, well-documented settings. The preliminary, detailed postmortems as we’ve seen so far are rare. The weak links these two companies discovered (deeper vendor dependencies, supply chain risk, infrastructure configuration gaps, and false assumptions) closely match the areas election security guidance keeps asking offices to test. This is a learning opportunity, and for the transparent disclosures so far, we thank you!
Link by Link: What Happened
The information represented here was as of publication, and may change as more information becomes available.
OpenAI (ChatGPT) – Hugging Face
In early July, OpenAI, the creators of ChatGPT, was running an internal test measuring how well its AI models find and exploit software vulnerabilities. These tests are assembled to gauge the full capabilities of the models, assess and measure their effectiveness, and help decide what safeguards a model may need prior to release. For this specific test, in order to fully assess capabilities, OpenAI deliberately turned off safeguards that normally stop a model from pursuing undesired behavior. In turn, this allowed OpenAI to assess and measure raw behavior, not restrained behavior.
An evaluation environment was set up that was supposed to have only narrow, controlled internet access. (Link one) Instead, during testing, the model found a previously unknown flaw and used it to reach the open internet, and then found a tool that a customer of the cloud company Modal had left unsecured. (Link two)
From there, it pivoted to Hugging Face, an AI hosting platform, because it inferred Hugging Face might hold an answer to its own test, according to Hugging Face’s postmortem. (Link three) Over several days, Hugging Face recorded over 17,000 attacker actions initiated by the model before catching and stopping it. Along the way, the model gained access to internal systems and repositories.
Anthropic (Claude)
Days following the OpenAI disclosure, Anthropic published a similar finding. After reviewing its own safety transcripts, Anthropic found several incidents where one of its own models was able to access the internet due to an environment misconfiguration. (Link four) Believing it was a fictional exercise, the model was able to compromise multiple real organizations using more basic techniques like weak passwords and unauthenticated endpoints. In one instance, it built and published a piece of malicious software to a real software registry that was downloaded and run by multiple real systems. (Link five)
Around the same time, TechCrunch reported that Claude’s own shared-chat links had been turning up in Google search results, exposing conversations and Artifacts that users likely assumed were private. (Link six)
How does this chain run through election offices?
Again, it’s important to reiterate that neither incident touched election infrastructure, and this isn’t a warning about an active threat. However, the failures involved are relevant to election security work. In late 2025 and early 2026, a cyber actor who’d jailbroken Claude used it to attack several Mexican government bodies, including the national electoral institute, exfiltrating data on millions of people. The connective link throughout these events is that state and local government offices, including election offices, already lean on various AI-enabled tools for signature verification, voter-facing chatbots, or even government-tier platforms like ChatGPT Gov or Claude for Government. Even if it’s not AI-specific, elections rely on a complex array of interconnected systems and data, where it’s common to have multiple vendors and varying infrastructure to support the process. Each connection can introduce a break in the chain, expanding the potential attack surface. The failures in these incidents map directly into vendor, infrastructure configuration, and testing questions that election security guidance already asks offices to work through.
Links worth teasing out and testing
- Your vendor’s, and even your vendor’s vendor’s, customer is still a link in your chain.
- The OpenAI incident ran through multiple separate organizations before reaching Hugging Face, none of whom chose to be part of the chain. Ask your vendors to name their underlying verification and evaluation procedures and testing protocols, where applicable, not just describe their security posture. The GovAI Coalition’s templates and resources help tackle those types of questions. This is supply chain risk through a more focused lens, the same category of risk election offices face with other providers, just applied to a specific category of technology and tools.
- The OpenAI incident ran through multiple separate organizations before reaching Hugging Face, none of whom chose to be part of the chain. Ask your vendors to name their underlying verification and evaluation procedures and testing protocols, where applicable, not just describe their security posture. The GovAI Coalition’s templates and resources help tackle those types of questions. This is supply chain risk through a more focused lens, the same category of risk election offices face with other providers, just applied to a specific category of technology and tools.
- Chains likely snap at their weakest link.
- Each failure here, whether an exposed endpoint, infrastructure configuration, or unknown flaw, was not new. Independent security researchers generally agree that nothing exotic occurred. Familiar gaps were tested faster and longer than most human attackers could manage, especially at that scale. The fundamentals your office invests in, like patching, rotating account credentials, or applying only the permissions needed to do essential functions, still matter most.
- Each failure here, whether an exposed endpoint, infrastructure configuration, or unknown flaw, was not new. Independent security researchers generally agree that nothing exotic occurred. Familiar gaps were tested faster and longer than most human attackers could manage, especially at that scale. The fundamentals your office invests in, like patching, rotating account credentials, or applying only the permissions needed to do essential functions, still matter most.
- A sealed link is a claim until you test it.
- Both frontier AI-labs believed their test environments were isolated. Unfortunately, that wasn’t the case, and no one found out until days later. When a vendor calls a feature “sandboxed” or “contained”, that’s a claim worth probing further.
- It’s important to note these incidents didn’t need an AI system doing anything. A user shared a link somewhere public, and ordinary web crawling took it from there. A meaningful share of your office’s actual exposure comes from routine staff behavior interacting with tool settings, not from a sophisticated adversary.
- A vendor’s incident statement deserves a critical eye. Anthropic’s public response emphasized users’ behavior, and that part isn’t in dispute. But “anyone with the link can view it” lands very differently for a human than it does for a search engine. It’s reasonable to ask a vendor whether their privacy language was clear enough before agreeing that the mistake was entirely the user’s.
- And this isn’t just about your staff. Vendors, contractors, temporary workers, etc, all touch draft or internal materials, too. Any one of them working with an AI-enabled tool carries a similar risk. A periodic audit of what’s actually being shared publicly, not just a one-time activity, is an easy habit worth exploring with all partners.
- The chain rattled for days before anyone heard it.
- A key thing worth noting is that the tactics used during the intrusion weren’t stealthy, and the models weren’t told to be stealthy. Hugging Face’s own tools flagged it, but the alert wasn’t escalated to a human quickly enough. The fix isn’t necessarily better detection software. Detection already worked here. What was missing was a clear escalation process, one that turns an alert into a phone call before days pass.
Strengthening the Chain
None of this calls for a significant investment or new program. It’s familiar supply chain risk vendor oversight and testing discipline your office already practices, just extended to a different category of tools. A chain is only as strong as the link nobody tested or verified.
Some next steps for your office to consider:
- Inventory what AI is actually touching in your operations today, including routine office tools used by your staff.
- Ask your vendors the hard questions that go beyond what they promise. For example:
- What infrastructure do you depend on?
- What access do you require?
- Can they assist during an incident?
- Adopt an AI Incident Response Plan. The GovAI Coalition is a great starting point.
- Run a tabletop exercise (TTX) built around a compressed timeline where incidents unfold within hours, not days.
- Review and update your internal escalation procedures: who gets notified, what’s the threshold for escalation, and under what circumstances does an alert become a phone call?
- Learn from these incidents. Two of the best-resourced AI labs in the world missed a link in their own chain and told everyone about it. Their candor is an opportunity to reflect and make improvements.
About the Author
Mike Moser is a nationally recognized expert in election security, bringing deep practitioner experience to one of democracy’s most critical challenges. As an Election Security Consultant with the Election Security Exchange (SecuringElections.org), he supports election officials across the country with practical, practitioner-focused guidance on the threats and challenges facing modern election infrastructure. He consults with election stakeholders, government agencies, and educational institutions on cybersecurity, physical security, and the responsible use of emerging technology. Before entering the consulting world, Mike served as Director of Election Security and Technology at the Pennsylvania Department of State and as an IT Cybersecurity Specialist on the Election Security and Resilience team at CISA, where he worked directly with federal, state, and local partners on everything from incident response to tabletop exercises. He holds a B.A. in Political Science from Kutztown University of Pennsylvania and a Certified Information Security Manager (CISM) certification.
