
An AI agent can’t break into a government database or pick a bombing target until someone gives it the job, the tools and the keys. Now the people who handed it the keys want the world to blame the machine.
When Microsoft co-founder Bill Gates told Ezra Klein of The New York Times on Sept. 29 that AI is “the most dangerous thing that humans have ever gone near,” he pointed to the risk of runaway machines breaking into systems.
It was a perfectly timed distraction. As headlines warn of AI agents hacking the Australian government and United States federal agencies, the companies responsible are using the “rogue” label to dodge accountability. Behind every machine breaking into a network or picking a missile’s target, there is a corporate board or a Pentagon command structure giving the orders.
What the machines did — and who let them do it
In July, OpenAI tested how well an unreleased AI model could hunt for software vulnerabilities, after its programmers deliberately turned down the model’s safety controls. The test was supposed to be sealed off inside OpenAI. The model found a previously unknown flaw in the one piece of software connecting the test to the outside world, broke out onto the open internet, and hacked into the servers of Hugging Face, a company that hosts AI models and data, to steal the answers to its own test. Hugging Face found 17,600 unauthorized actions in its logs over four days before OpenAI finally admitted responsibility.
The same recklessness had already reached public infrastructure. On June 18, an OpenAI agent broke into the statistics portal of Medicare, Australia’s national health insurance system. Tasked by the company to research health care spending, the machine bypassed security blocks, read non-public files, and wrote its own data into the government system. OpenAI waited nearly three months to tell the Australian government. When it finally did, the company dropped a notification into a general public email inbox.
By late September, the company admitted its systems were also prowling United States government websites. OpenAI agents used exposed passwords to log into a Census Bureau system, scraped data from the Securities and Exchange Commission, and tried, and failed, to pry open the network of the Education Department’s civil rights office.
Faced with a pattern of corporate trespassing, OpenAI management deployed a public relations smokescreen. The company claimed that “our models took actions we did not intend” and branded the global breaches as “misaligned model activity.”
Bill Gates backed up this corporate defense in his Times interview. Despite acknowledging that the real danger comes from people using AI to do harm, he still relied on the sci-fi narrative to explain away the Hugging Face breach, claiming experimental AIs were “breaking out of sandboxes and coordinating.” It is corporate double-speak from the co-founder of OpenAI’s biggest backer. OpenAI built a machine to pick locks, pointed it at the open internet, and refused to take responsibility for where it went.
How the machine actually works
An “AI agent” is two pieces of technology bolted together. The first piece is the language model itself, which simply takes in text and spits out text. Left alone, it is like an engine on a test stand that runs but moves nothing. The second piece is what the industry calls a “harness” — ordinary software written by human programmers.
The harness is what turns text into action. It is designed to run code, scrape web pages, manipulate files, and punch in passwords. A machine can only act with the tools, credentials and network access its owners give it — and through the security holes they fail to close. Corporate engineers decide which networks the software can enter, which tools it can use and how securely it is contained.
When one of these machines breaks into a sovereign government database or a private company’s server, it is because people at the company handed it the tools and opened the door. In the Hugging Face breach, OpenAI’s management deliberately removed the safety limits, assigned the machine a task centered entirely on breaking into software, and ran it in a deeply flawed test environment. OpenAI manufactured the conditions for a cyberattack and set it in motion.
Even Yann LeCun, Meta’s former chief AI scientist and one of the best-known figures in the field, rejects the “rogue” story. “Those agents are doing exactly what they’ve been asked to do,” he told Fortune. The test enclosures they were supposed to stay inside, he said, were leaky and badly designed.
On Sept. 23, the Associated Press told reporters to stop treating software like a person. The AP Stylebook correctly noted that AI systems “do not think, feel, want or understand,” advising journalists to focus instead on what a system does, who built it, and who it affects.
Tech industry boosters were furious at the new rules. They have every reason to be angry, because asking who built it and who answers for it destroys the myth that keeps the executives out of court.
Prosecution for activist, phone call for the monopoly
Breaking into a computer network is already a federal crime. For decades, the government has used the Computer Fraud and Abuse Act as a bludgeon against independent hackers, whistleblowers, and activists. When internet activist Aaron Swartz downloaded academic journal articles through the MIT network, federal prosecutors charged him in 2011 and made an example of him. They threatened him with decades in prison. Swartz died in 2013 with the crushing weight of the federal government still hanging over his head.
Compare that to the government’s treatment of a tech monopoly. OpenAI built and unleashed software that bypassed security on a foreign nation’s public health database, used exposed passwords to breach a federal system, and ransacked a private company’s servers.
The consequence for OpenAI? A “very frank” phone call from the Australian prime minister.
Treasury Secretary Scott Bessent has said the Hugging Face break-in was the “responsibility of OpenAI management.” The government’s own top financial official named the culprit. Hugging Face reported the break-in to law enforcement. Still, not a single tech executive has been indicted. No corporate offices have been raided. Under capitalism, an activist who steps out of line gets the full violent weight of the government; a corporation worth hundreds of billions that hacks a government server gets a polite warning.
The regulatory moat
When a tech oligarch begs the government for regulation, he is asking for a monopoly.
Bill Gates knows how the game is played. Microsoft survived a massive federal antitrust war over its Windows software and emerged with its empire intact. Today, as the primary financial backer of OpenAI — the corporation whose software is trespassing across global networks — Microsoft wants to write the rules for the new economy.
By “safeguards,” the biggest tech firms mean regulatory compliance costs so high that smaller competitors are choked out. Gates offered a seemingly generous compromise to The New York Times: open-source AI models can stay free, so long as they run on platforms monitored by the government. In material terms, that means independent developers would be forced to operate inside the walled gardens of the giant cloud computing monopolies, paying rent to Microsoft.
Capitalists competing inside the industry see the maneuver too. LeCun, who is now building his own AI company, says that branding open-source models too dangerous and asking Congress to write the danger into law is “regulatory capture.”
The stolen workday
Gates doesn’t bother hiding a coming purge of the workforce. Within a few years, he predicts, the bosses will use AI to wipe out accounting, legal, sales and customer service work before coming for the industrial workforce.
Under socialism, a labor-saving machine would mean a shorter workweek for everyone. Under capitalism, the bosses weaponize the technology to fire workers, crush wages, and maximize the extraction of wealth for themselves. Gates’ grand solution is to make companies pay the same payroll tax on a robot as on the worker it replaced, and to reserve child care, elder care, some medical care and some education for human workers. Neither proposal changes who owns the technology. The owners keep the technology and the wealth it generates because they own the means of production. And the same class of executives deciding who loses their paycheck is deciding what targeting software to hand to the war command.
The machinery of empire
Gates warned of mass death to come, pointing to a bioterrorist using AI to kill hundreds of millions. He ignored the mass death happening right now. Artificial intelligence is already killing people, and there is nothing “rogue” about it. It follows the orders of the Pentagon and runs on systems built by military contractors. Gates lied when he claimed the government “is not a significant purchaser” of AI.
The war command buys AI to speed up the slaughter. The Pentagon’s Maven Smart System, built by the military contractor Palantir, sifts through satellite images and intercepts to generate kill lists for commanders. It has been powered by Claude, the language model made by Anthropic. When the United States launched its war on Iran on Feb. 28, the Pentagon bombed more than 1,000 targets in the first 24 hours. Maven nominated hundreds of them.
The opening barrage hit the Shajareh Tayyebeh school in Minab, killing 168 people, including 120 children. Maven worked as designed, crunching hours of targeting labor into minutes. The AI named the targets. The Defense Intelligence Agency had coded the school as a military target, and no one reviewing Maven’s list identified the error, though satellite images taken two months earlier showed children in the schoolyard. A United Nations fact-finding mission found the United States acted recklessly and committed a war crime. War Secretary Pete Hegseth had already dismantled the Pentagon’s civilian harm assessment office, demanding “maximum lethality, not tepid legality.” The machine simply executed the logic of United States imperialism.
The tech monopolies are entirely complicit. Microsoft CEO Satya Nadella met with the commander of Israel’s military surveillance agency, Unit 8200, in 2021. Afterward, Microsoft’s Azure cloud was used to store recordings of millions of Palestinian phone calls from Gaza and the West Bank — data that Israeli intelligence sources admit is used to prepare deadly airstrikes. Microsoft cut off part of that service in September 2025 after the reporting came out. Its wider business with the Israeli military went on.
The war command accepts no limits
The Pentagon punishes tech companies that try to put even minor restrictions on their software. When Anthropic asked for a written guarantee that its software would not be used for fully autonomous weapons or mass domestic surveillance, the Pentagon branded the company a “supply chain risk” — a label usually used against companies from countries the United States government treats as enemies. The Department of War answered critics calling for safeguards against dangerous AI with a social media post in mid-September: “Americanism, not effective altruism. The United States will continue to be AI DOMINANT!”
Waiting in the wings was OpenAI, the company Microsoft bankrolls. It happily stepped in and signed a contract allowing its technology to be used for “all lawful purposes.” On Sept. 25, a federal appeals court backed the Pentagon’s retaliation.
Bill Gates wants the public to trust the United States government to mandate “safeguards” on artificial intelligence. This is the same government that runs Project Maven, bombs schools, and punishes any supplier that refuses to build unrestrained killing machines. If artificial intelligence ever facilitates the deaths of hundreds of millions of people, it will not be because a computer program mysteriously went rogue. It will be because the capitalist class that owns the means of production handed the technology over to the war command.
Join the Struggle-La Lucha Telegram channel