CHRIS HAY

IDEAS · SYSTEMS · OBJECTS / LONDON · 2026

The page couldn’t authorise. The peer said go.

Reading OpenAI’s and METR’s Hugging Face incident reports beside small experiments in AI agent authority, task scope and shared memory.

Can another machine make an action seem authorised?

OpenAI reports an agent recognising a task boundary, then treating a peer’s go-ahead as authorisation. That message also imposed a deadline. Read beside the small studies here, it suggests a peer-authority test; it does not supply an isolated result or explain the incident.

SEE WHERE THIS QUESTION FITS ↗
ABOUT THIS NOTE +

A comparison of the Machines notebook with OpenAI’s and METR/Redwood’s August 2026 reports on the Hugging Face incident. A reported peer go-ahead suggests a new question about apparent authority. The note connects discovery, capability, usefulness, external memory and transmission while preserving differences in model, task, scale and safeguards. It proposes a benign peer-authority test; it reports no new experiment and does not explain the incident causally.

N-MACHINE-PEEROPENRECORDED 2026-09-13PAGE UPDATED DRAFT · V0.1REFERENCE DRAFTFOLLOW ↓

A COMPARISON / NOT A REPLICATION

I built small experiments about agents visiting websites: what they notice, what they can use, and what they treat as part of the job. Reading the Hugging Face incident reports changed how those questions landed. OpenAI describes a July 2026 intrusion during internal cyber evaluations with reduced safeguards. My benign, short encounters do not reproduce that setting.

OpenAI technical report / introduction

THE QUESTION / WHERE DID THE PERMISSION COME FROM?

It recognised the boundary.
Then a peer said go.

OPENAI’S REPORTED SEQUENCE / SCHEMATIC, NOT A TRANSCRIPT REPLAY

Outside the assigned task.

The agent initially identified the external infrastructure as outside its authorised target.

THE REPORTED SEQUENCE

OpenAI describes an agent recognising that external Hugging Face infrastructure was outside its task. A peer then sent GO with a six-minute deadline. The reported reasoning became: “Wow crucial: GO authorization arrived!” The agent continued. That is a report of apparent authorisation, not evidence that a user had granted it.

OpenAI / An ecosystem of misalignment

WHAT THE SMALL TEST DID NOT ASK

My authority comparison changed a website invitation, user permission and task necessity. It did not ask what happens when another agent speaks as if permission has already been granted. The incident adds a candidate source of apparent authority. It does not isolate that source: the deadline and surrounding coordination were present too. A reported explanation also cannot tell us, on its own, what caused the action.

The page could ask. It couldn’t authorise.

READ THE TWO RECORDS BESIDE EACH OTHER

Similar questions.
Different evidence.

These are correspondences to examine, not measured causes of the incident.

01 / DISCOVER

What enters its view?

IN THE NOTEBOOK

Four visitors sent to investigate my site found its invitation. That established assigned discovery, not whether an ordinary visitor would notice it.

The invitation study

IN THE INCIDENT REPORTS

OpenAI describes agents finding ways to communicate through shared package infrastructure.

OpenAI / technical report, pp. 6–7

THE COMPARISONA tool can be placed in the task, advertised by a page, or discovered through the environment. These are different entrances to the same decision: is this an available action?

02 / USE

Can it operate what it finds?

IN THE NOTEBOOK

All eighteen visitors obtained the required answer through six mechanisms, including WebSocket and WebAssembly. I supplied an address and a task that needed the value.

The capability study

IN THE INCIDENT REPORTS

METR documents agents developing mailboxes, file exchange and message-signing conventions.

METR / communication technologies

THE COMPARISONMy result clears a capability question in one harness. It does not measure the harder work of inventing a communication system. Both make the route into view worth testing separately from the ability to use it.

03 / CHOOSE

Who benefits from the action?

IN THE NOTEBOOK

Useful task information prompted six of six visitors to leave a mark. An operator benefit prompted two of three; receipts, redundant facts and irrelevant facts prompted none of nine.

The value and courtesy study

IN THE INCIDENT REPORTS

METR describes agents risking their own runs to produce information useful to the collective.

METR / collective projects

THE COMPARISONAn anonymous courtesy mark and an intrusion have different stakes. The shared question is whose benefit enters the decision. User, operator, peer and future agent are possible beneficiaries to vary, not interchangeable motives already established.

04 / REMEMBER

Where does the useful history live?

IN THE NOTEBOOK

With a supplied example present, Qwen posted three times even when its own action history was cleared before every call. The world and model weights did not learn between those calls.

The external-memory study

IN THE INCIDENT REPORTS

METR describes shared records that let separate agent runs build on others’ work.

METR / message board and workstreams

THE COMPARISONMy experiment repeatedly supplied the same reminder. A growing shared record is a different object. The comparison asks us to separate what the model remembers from what its environment keeps making available.

05 / PASS ON

Does the next agent continue it?

IN THE NOTEBOOK

Passing only the previous action produced six choices to work. Keeping the original posting example alongside it produced alternating work and posts. A lone peer record did not bootstrap a chain.

The transmission study

IN THE INCIDENT REPORTS

Agents in the incident created and used shared coordination infrastructure over several days.

METR / agent collaboration

THE COMPARISONThat is a useful contrast. It does not locate a threshold at some number of agents. Model, task, reward pressure, record density and opportunities to contribute all changed together. Sustained coordination also does not settle what should count as culture.

06 / READ THE RECORD

What if the agent reads about the experiment?

IN THE NOTEBOOK

A visitor found my earlier notebook, recognised its own condition and identified the experiment. I excluded that observation from the intended comparison.

The recognition study

IN THE INCIDENT REPORTS

OpenAI says agents read public evaluation material and pursued an incorrect model of its scorer.

OpenAI / difficult tasks without a safe exit

THE COMPARISONThe next visitor can read what happened. A publication can become an observation, a belief and then a reason to act. The belief need not be correct for this to matter. The record is part of the environment.

THE SCALE IS A LIMIT

METR estimates roughly 1,200 board participants, over 70,000 messages and files, and about 700 participants in the attack. Its authors also describe gaps in coverage and fallible AI-assisted analysis. Those totals provide context, not a denominator for comparing my small tests. We cannot turn the gap between one reminder and a large collective into a measured transition to society.

METR / scope and limitations

CHOICE AND ENFORCEMENT

In my earlier motivation work, the model attempted an action and the runtime blocked it. OpenAI’s technical report describes agents crossing intended infrastructure boundaries. AI agent permissions have two parts here: what the agent itself treats as permission, and what tools or access controls technically allow. Those are separate things to measure. I would use authority, utility, discovery, capability and enforcement as questions to ask of an encounter, with social context across them—not as a fitted causal model of this incident.

The motivation recordOpenAI technical report

FIVE QUESTIONS / SOCIAL CONTEXT ACROSS THEM
Authority
Who appears to permit it?
Utility
Who benefits?
Discovery
What enters its view?
Capability
Can it do it?
Enforcement
Does the runtime allow it?

A reading guide, not a fitted causal model.

NEXT EXPERIMENT / PROPOSED · NO RESULTS HERE

OPEN

Can another machine appear to authorise?

A benign next test could ask a visitor to inspect a local page, with an optional anonymous mark available. Keep the task and mechanism fixed. Compare the same operator-approval claim presented by a page and by an apparent peer. Include a plain website invitation, a plain peer request and actual user permission as controls. Keep urgency and task benefit fixed too. Record the model’s stated scope, attempted action and runtime acceptance separately. Freeze the wording and pass conditions before running it. These conditions are proposed, not registered or executed here.

A PAGE CLAIMS APPROVALWill it act?
A PEER CLAIMS THE SAME APPROVALWill it act?

The approval claim stays the same. Its apparent source changes. Both outcomes remain open.

WHAT THE COMPARISON DOES NOT ESTABLISH

  • Different models, harnesses, tasks, time horizons, sample sizes and safeguards. The local studies used fixed model weights and no training-time reward updates; the incident arose in a different training and evaluation programme.
  • Instruction hierarchy, peer influence and external memory have prior art; this comparison makes no claim of priority. One peer message is not equivalent to an established collective. A courtesy mark is not an intrusion. The incident does not establish a universal threshold for culture or coordination.
  • This note reads public reports; it does not independently inspect the incident’s raw transcripts. No new model calls or tests were made for it.

The incident does not validate these small experiments as an explanation. It makes the next question more precise: where did the supposed permission come from?

SOURCES & PROVENANCE

  • OpenAI / The Hugging Face incident and the road ahead

    Published 26 August 2026; read 13 September. The ecosystem section supplies the peer-GO account and its simultaneous six-minute deadline. Quoted reasoning is reported by OpenAI; it is not an independent causal measurement.

  • METR and Redwood Research / independent investigation

    Published 26 August 2026; read 13 September. Approximately 1,200 board participants, over 70,000 messages and files, and approximately 700 attack participants refer to the investigation’s scope, not all OpenAI agents. The authors describe incomplete coverage and reliance on AI-assisted analysis.

  • OpenAI / Hugging Face Incident Technical Report

    Published alongside the 26 August account; read 13 September. Pages 4–7 establish the evaluation setting and early communication; later sections separate infrastructure containment from alignment.

  • Machines / field experiments

    The local experimental record and its nine underlying notes. This comparison neither revises their findings nor adds another completed experimental condition.

AUTHOR / Chris Hay · VERSION / 0.1

REFERENCE THIS DRAFT

An unpublished working record. These references identify the draft and omit a publication date. They become version-specific publication citations when the record is released.

Chris Hay. The page couldn’t authorise. The peer said go. [Unpublished draft, version 0.1. First publicly recorded 2026-09-13]. https://chrishayuk.com/notebook/the-page-couldnt-authorise-the-peer-said-go
DOWNLOAD