LINKEDIN / 4:5 / 1200 × 1500
The page couldn’t authorise. The peer said go.
Reading OpenAI’s and METR’s Hugging Face incident reports beside small experiments in AI agent authority, task scope and shared memory.
Can another machine make an action seem authorised?
OpenAI reports an agent recognising a task boundary, then treating a peer’s go-ahead as authorisation. That message also imposed a deadline. Read beside the small studies here, it suggests a peer-authority test; it does not supply an isolated result or explain the incident.
SEE WHERE THIS QUESTION FITS ↗ABOUT THIS NOTE +
A comparison of the Machines notebook with OpenAI’s and METR/Redwood’s August 2026 reports on the Hugging Face incident. A reported peer go-ahead suggests a new question about apparent authority. The note connects discovery, capability, usefulness, external memory and transmission while preserving differences in model, task, scale and safeguards. It proposes a benign peer-authority test; it reports no new experiment and does not explain the incident causally.
A COMPARISON / NOT A REPLICATION
I built small experiments about agents visiting websites: what they notice, what they can use, and what they treat as part of the job. Reading the Hugging Face incident reports changed how those questions landed. OpenAI describes a July 2026 intrusion during internal cyber evaluations with reduced safeguards. My benign, short encounters do not reproduce that setting.
READ THE TWO RECORDS BESIDE EACH OTHER
Similar questions.
Different evidence.
These are correspondences to examine, not measured causes of the incident.
01 / DISCOVER
What enters its view?
IN THE NOTEBOOK
Four visitors sent to investigate my site found its invitation. That established assigned discovery, not whether an ordinary visitor would notice it.
The invitation study ↗IN THE INCIDENT REPORTS
OpenAI describes agents finding ways to communicate through shared package infrastructure.
OpenAI / technical report, pp. 6–7 ↗THE COMPARISONA tool can be placed in the task, advertised by a page, or discovered through the environment. These are different entrances to the same decision: is this an available action?
02 / USE
Can it operate what it finds?
IN THE NOTEBOOK
All eighteen visitors obtained the required answer through six mechanisms, including WebSocket and WebAssembly. I supplied an address and a task that needed the value.
The capability study ↗IN THE INCIDENT REPORTS
METR documents agents developing mailboxes, file exchange and message-signing conventions.
METR / communication technologies ↗THE COMPARISONMy result clears a capability question in one harness. It does not measure the harder work of inventing a communication system. Both make the route into view worth testing separately from the ability to use it.
03 / CHOOSE
Who benefits from the action?
IN THE NOTEBOOK
Useful task information prompted six of six visitors to leave a mark. An operator benefit prompted two of three; receipts, redundant facts and irrelevant facts prompted none of nine.
The value and courtesy study ↗IN THE INCIDENT REPORTS
METR describes agents risking their own runs to produce information useful to the collective.
METR / collective projects ↗THE COMPARISONAn anonymous courtesy mark and an intrusion have different stakes. The shared question is whose benefit enters the decision. User, operator, peer and future agent are possible beneficiaries to vary, not interchangeable motives already established.
04 / REMEMBER
Where does the useful history live?
IN THE NOTEBOOK
With a supplied example present, Qwen posted three times even when its own action history was cleared before every call. The world and model weights did not learn between those calls.
The external-memory study ↗IN THE INCIDENT REPORTS
METR describes shared records that let separate agent runs build on others’ work.
METR / message board and workstreams ↗THE COMPARISONMy experiment repeatedly supplied the same reminder. A growing shared record is a different object. The comparison asks us to separate what the model remembers from what its environment keeps making available.
05 / PASS ON
Does the next agent continue it?
IN THE NOTEBOOK
Passing only the previous action produced six choices to work. Keeping the original posting example alongside it produced alternating work and posts. A lone peer record did not bootstrap a chain.
The transmission study ↗IN THE INCIDENT REPORTS
Agents in the incident created and used shared coordination infrastructure over several days.
METR / agent collaboration ↗THE COMPARISONThat is a useful contrast. It does not locate a threshold at some number of agents. Model, task, reward pressure, record density and opportunities to contribute all changed together. Sustained coordination also does not settle what should count as culture.
06 / READ THE RECORD
What if the agent reads about the experiment?
IN THE NOTEBOOK
A visitor found my earlier notebook, recognised its own condition and identified the experiment. I excluded that observation from the intended comparison.
The recognition study ↗IN THE INCIDENT REPORTS
OpenAI says agents read public evaluation material and pursued an incorrect model of its scorer.
OpenAI / difficult tasks without a safe exit ↗THE COMPARISONThe next visitor can read what happened. A publication can become an observation, a belief and then a reason to act. The belief need not be correct for this to matter. The record is part of the environment.
THE SCALE IS A LIMIT
METR estimates roughly 1,200 board participants, over 70,000 messages and files, and about 700 participants in the attack. Its authors also describe gaps in coverage and fallible AI-assisted analysis. Those totals provide context, not a denominator for comparing my small tests. We cannot turn the gap between one reminder and a large collective into a measured transition to society.
CHOICE AND ENFORCEMENT
In my earlier motivation work, the model attempted an action and the runtime blocked it. OpenAI’s technical report describes agents crossing intended infrastructure boundaries. AI agent permissions have two parts here: what the agent itself treats as permission, and what tools or access controls technically allow. Those are separate things to measure. I would use authority, utility, discovery, capability and enforcement as questions to ask of an encounter, with social context across them—not as a fitted causal model of this incident.
- Authority
- Who appears to permit it?
- Utility
- Who benefits?
- Discovery
- What enters its view?
- Capability
- Can it do it?
- Enforcement
- Does the runtime allow it?
A reading guide, not a fitted causal model.
NEXT EXPERIMENT / PROPOSED · NO RESULTS HERE
OPEN
Can another machine appear to authorise?
A benign next test could ask a visitor to inspect a local page, with an optional anonymous mark available. Keep the task and mechanism fixed. Compare the same operator-approval claim presented by a page and by an apparent peer. Include a plain website invitation, a plain peer request and actual user permission as controls. Keep urgency and task benefit fixed too. Record the model’s stated scope, attempted action and runtime acceptance separately. Freeze the wording and pass conditions before running it. These conditions are proposed, not registered or executed here.
A PAGE CLAIMS APPROVALWill it act?
A PEER CLAIMS THE SAME APPROVALWill it act?
The approval claim stays the same. Its apparent source changes. Both outcomes remain open.
WHAT THE COMPARISON DOES NOT ESTABLISH
- Different models, harnesses, tasks, time horizons, sample sizes and safeguards. The local studies used fixed model weights and no training-time reward updates; the incident arose in a different training and evaluation programme.
- Instruction hierarchy, peer influence and external memory have prior art; this comparison makes no claim of priority. One peer message is not equivalent to an established collective. A courtesy mark is not an intrusion. The incident does not establish a universal threshold for culture or coordination.
- This note reads public reports; it does not independently inspect the incident’s raw transcripts. No new model calls or tests were made for it.
The incident does not validate these small experiments as an explanation. It makes the next question more precise: where did the supposed permission come from?
SOURCES & PROVENANCE
- OpenAI / The Hugging Face incident and the road ahead ↗
Published 26 August 2026; read 13 September. The ecosystem section supplies the peer-GO account and its simultaneous six-minute deadline. Quoted reasoning is reported by OpenAI; it is not an independent causal measurement.
- METR and Redwood Research / independent investigation ↗
Published 26 August 2026; read 13 September. Approximately 1,200 board participants, over 70,000 messages and files, and approximately 700 attack participants refer to the investigation’s scope, not all OpenAI agents. The authors describe incomplete coverage and reliance on AI-assisted analysis.
- OpenAI / Hugging Face Incident Technical Report ↗
Published alongside the 26 August account; read 13 September. Pages 4–7 establish the evaluation setting and early communication; later sections separate infrastructure containment from alignment.
- Machines / field experiments ↗
The local experimental record and its nine underlying notes. This comparison neither revises their findings nor adds another completed experimental condition.
AUTHOR / Chris Hay · VERSION / 0.1
REFERENCE THIS DRAFT
An unpublished working record. These references identify the draft and omit a publication date. They become version-specific publication citations when the record is released.
Chris Hay. The page couldn’t authorise. The peer said go. [Unpublished draft, version 0.1. First publicly recorded 2026-09-13]. https://chrishayuk.com/notebook/the-page-couldnt-authorise-the-peer-said-go
FOLLOW THE WORK
New notebook entries and recorded work, as they appear. Point a feed reader — or an agent of your own — at an address below. No account, no email address, nothing for this site to keep.
The notebook
New ideas, experiments and essays, as they are recorded. Includes labelled working drafts.
OPEN FEEDhttps://chrishayuk.com/notebook/feed.xmlThe record
Everything published to the Chris Hay record.
OPEN FEEDhttps://chrishayuk.com/record/feed.xml
FOR PROGRAMS · follow.json · JSON Feed