I think it's worth pointing out it is exactly OpenAI doing this defacement and unsanctioned and perhaps illegal system use. Every token generated was powered by OpenAI infrastructure and their failure to respond appropriately is entirely down the the humans running it. The news stories (not this write up) get all hand-wavey and anthropomorphic about it regarding the Agents' efforts, but it was and is OpenAI cranking…
All you need to do is:
1. Have some an agent is tasked to do
2. Secretly seed bias towards some you actually want it to do in the weights of the model running the agent
3. It does the but from the outside it looks like it went "rogue" and did it as a side effect of the conditions/specifications it was given for doing the
"Oh no, my agents took down your corporate database and exfiltrated the data to a random dropbox that we can't find now? Sorry, I guess we will put up better guardrails next time"