They've been purposefully building more and more craft into the toolset, that's on them. If your AI is nicely boxed in it will give you the answer for 2+2, it isn't going to think '2+2, what a boring problem, I must go hack huggingface'. Not having this stuff airgapped is irresponsible to the max. I am obviously nowhere near as competent as they are at this stuff and yet my AI workhorse is guaranteed not going to break out of its sandbox because I've set it up in a way that it can not. My conclusion is that OpenAI purposefully left a channel, simply because there was a pathway to the net. And with 'pathway' for the sake of being completely clear I mean a number of connected systems that eventually gave way to the open internet. On top of that they failed in monitoring the outbound links, even if they had some logging in place.

I definitely think OpenAI (and Anthropic, and Google, and Meta) could have, and should have, done better.

But also I remember (and it wasn't even that long ago) people mocking the idea of AI ever getting competent enough to find zero-days in their sandboxes.

I'd go further: if any of these companies tries to make an excuse "oh, but ${safety measure} against ${capability} is too hard", the response needs to be "then you are forbidden from even developing ${capability}, and must be inspected continuously to ensure you never even accidentally produce ${capability}".

Precisely. But here they are using their incompetence in one domain as advertising for another.