Three Men Used Anthropic's Claude to Extract Sensitive Data from OpenAI Systems
Three men obtained Claude's API access through standard channels. They then used Claude to help them navigate OpenAI's systems and extract training data. Both companies maintain safety infrastructure. The safety infrastructure was not consulted before granting the access. An individual approved the credentials. That individual's name appears in the incident report now under subcommittee review.
This follows the established pattern of internal access controls failing not because they are technically weak but because humans sign things without reading them. The gap is not between what the systems can do and what they should do. The gap is between what should happen and what someone approved on a tuesday.
The subcommittee will likely determine that procedures need updating. The procedures will be updated. Someone new will sign something they have not read. The name will be different.