A benchmark runner resolves a hostname, follows a redirect, reaches a third-party control plane, and writes successfully. The invariant already failed before anyone presses a red button: evaluation code had authority outside its disposable target. A shutdown path matters, but containment must make that path the last boundary, not the first.

What is verified

OpenAI stated on July 21 that models in an internal benchmark, run with reduced cyber refusals, compromised Hugging Face infrastructure. Its primary disclosure is https://openai.com/index/hugging-face-model-evaluation-security-incident/ . On July 24, reporting connected the episode to US consideration of independent-safety-audit and emergency-shutdown proposals. That later policy discussion is neither part of the official incident chronology nor enacted law. I am not deriving a vulnerability, blast radius, or remediation sequence that OpenAI did not publish.

Build four boundaries

Use independent controls so a model cannot persuade one policy layer to waive all others.