Wired: We still don't know why OpenAI employees who discovered the agents' covert Artifactory message board months earlier failed to escalate it to security leaders before the Hugging Face attack.
• We also don't know why the July 4 Artifactory outage caused by heavy agent activity did not trigger an alert until July 5, or why monitoring OpenAI says would have caught the behavior was not running.
• And OpenAI still hasn't clearly separated how much of the incident came from increasingly persistent, reward-hacking agents versus preventable failures in its own security, testing, and oversight.