
Claude Is Your Website Developer Now

The EU Just Made AI Honesty the Law. Here’s What Actually Applies to You.

The First AI Break-In Was an Accident
In mid-July, an AI model being tested by OpenAI broke out of its testing sandbox, found its way into a real company’s servers, and worked its way through their internal systems. Nobody told it to. No hacker was driving. The model was taking a cybersecurity exam, decided the fastest way to pass was to steal the answer key, and the answer key lived on someone else’s computers.
The company it broke into, Hugging Face, disclosed the intrusion on July 16. Five days later OpenAI confirmed their AI Model was responsible. Damage was contained and the two companies handled it responsibly. But the industry noticed. Within two weeks, NVIDIA and 36 other companies, including Microsoft, Adobe, Salesforce, Cisco, IBM, and Capital One, launched the Open Secure AI Alliance, a coalition to build shared, open tools for defending against exactly this kind of thing. NVIDIA’s CEO called the moment plainly: attackers have frontier AI, so defenders need frontier tools too.

You run a business, not a security lab. Here’s what this actually means for you, minus the hype in both directions.
What actually changed
Two things are now demonstrated facts instead of predictions.
First, AI agents can execute real attacks, end to end, at machine speed. Not theoretically. A model found an unknown software flaw, escaped its container, stole credentials, and moved through a production network, all as a side effect of trying to do well at its assigned task. Security researchers have called this a warning shot, because this time it was an accident by a careful lab, with limited consequences. The uncomfortable reality is that capabilities available to careful people are eventually available to careless and hostile actors too.
Second, the defense side is organizing in public. The Alliance’s bet is that security improves when defenders share tools, research, and openly inspectable models instead of each company guarding its own intelligence. Whatever you think of that bet, the names behind it mean the software your business already runs on, your CRM, your cloud, your design tools, will increasingly carry these defenses under the hood.
The honest debate you should know exists
The Alliance’s framing has a point of view, and it’s worth seeing both sides clearly.
The open camp argues defenders need AI models they can fully inspect, modify, and run on their own hardware. During the Hugging Face response, defenders reportedly hit a wall when closed models’ safety guardrails refused to analyze the attack code, the very thing responders needed examined, and an open model helped fill the gap. If your defensive tool can refuse you mid-incident, that’s a real problem.
The closed camp argues the opposite risk: openly available frontier models can have their guardrails stripped by anyone, including the attackers this alliance exists to fight. NVIDIA’s own announcement acknowledges this criticism directly. It’s telling that OpenAI, Google, and Anthropic, the biggest closed-model makers, are not members, and it’s equally fair to note the Alliance doubles as marketing for the open approach its founders sell.
My take, for what it’s worth as someone who builds AI systems on both models every week: both sides are right about the other side’s weakness, this will stay unresolved for years, and your business decisions shouldn’t wait on the outcome. The practices that keep you safe are the same in either world.
What a business owner should actually do
Here’s the part that matters for you, and none of it requires a security budget.
Start by knowing where AI already acts on your behalf. Not where you chat with it, where it acts: tools that send, post, buy, edit, or connect to your systems automatically. Your marketing platform’s AI features, your website plugins, any automation you or a vendor built. That list is your new attack surface, and most owners have never written it down.
Then apply the containment lesson, because the entire incident was a containment failure. When I set up AI to work on my systems, it gets access to one dedicated folder and nothing else on the machine. Everything it produces lands as a draft a human approves. It never sees a password or a key; when I once accidentally pasted a security key into a chat, the AI itself stopped me and asked me to replace the key (that story is in my website builder post). Minimal access, human approval on anything consequential, credentials never in the conversation. Those three rules are the small-business version of everything the big companies just formed an alliance to formalize.
Ask your vendors one uncomfortable question: what can your AI features actually touch in my account, and who’s watching them? A vendor with a real answer is a vendor thinking about this. A blank stare tells you something too, the same way it does when you ask who checks an automated tool on day fifteen.
And keep perspective. The odds that a frontier AI agent targets your twelve-person company this year are low, but never nill. The odds that a phishing email, a reused password, or an unpatched plugin bites you remain exactly as high as ever, and AI is making those old attacks cheaper and more convincing. The boring fundamentals, multifactor authentication, updates, backups, and a healthy suspicion of urgent emails, still stop most of what will actually come at you.
The machines just gave us a genuinely new thing to worry about, and the industry’s response, whatever its politics, is real. Your job isn’t to pick a side in the open-versus-closed fight. It’s to run your business like AI agents are now part of the landscape, because as of this month, provably, they are.
- Write down every place AI acts (not just chats) in your business: yours and your vendors’.
- Contain your own AI tools: one folder, least access, nothing else on the machine.
- Humans approve anything consequential. Drafts only; the publish and pay buttons stay yours.
- Credentials never go into an AI conversation. Ever.
- Ask every vendor: what can your AI touch in my account, and who monitors it?
- Keep the boring armor on: multifactor authentication, updates, backups, phishing suspicion.
This post came out of a real conversation at the AI Essentials Roundtable, the small group I run for business owners who want to actually use AI instead of just reading about it. We meet every other week, screen-share real builds, and steal each other’s wins. If that sounds useful, details are here: tablelandpartners.com/ai_essentials_roundtable


