×
How burning Waymos became the image of the LA protests

How burning Waymos became the image of the LA protests

Is there a more potent image from the current anti-ICE protests in Los Angeles than a row of driverless Waymo vehicles covered in anti-ICE slogans and engulfed in flames?

At least five Waymos were destroyed during the protests over the weekend, CNN reports. And the company tells us that it has suspended its service in certain parts of the city under direction from the Los Angeles Police Department.

As we’ve seen before, Waymo’s autonomous vehicles have a way of turning into collateral damage during times of civil unrest. They are often sitting ducks, lacking an innate ability to avoid the scene or flee when surrounded by a group of people. Unlike Immigration and Customs Enforcement, they won’t run over protesters who stand in their way — their programming forbids it. And their presence likely adds fuel to a volatile situation, where protests against ICE and billionaire oligarchs are in coexistence. Waymo insists the protests aren’t related to its service, but it seems clear the robotaxis represent a change that a lot of people are unhappy about.

1/5

LOS ANGELES, CALIFORNIA – JUNE 08: A person spray paints a Waymo car during immigration raid protests on June 08, 2025 in Los Angeles, California. Tensions in the city remain high after the Trump administration called in the National Guard against the wishes of city leaders following two days of clashes with police during a series of immigration raids. (Photo by Mario Tama/Getty Images)
Photo: Mario Tama / Getty Images

While the protesters aren’t rallying in opposition to the Alphabet-owned company, others watching from afar can’t help but draw some conclusions about the tech industry in general’s role in society today.

Critics note that Waymo’s robotaxis are festooned with cameras, which they use to perceive their environment and detect obstacles. But the cameras are also recording their surrounding environment and storing the footage. The company has been known to share that footage with law enforcement agencies, including the LAPD, when requested or subpoenaed. So it makes sense, these critics theorize, that protesters who are worried about their identities being revealed by rolling “surveillance devices” would seek to destroy them.

Waymo is a project of Google, whose CEO, Sundar Pichai, attended Donald Trump’s inauguration. And the company’s effort to replace human drivers with robots is a threat to blue-collar jobs — to say nothing of its work on AI and all the societal implications on labor and education that entails.

The destruction underscores a serious obstacle to Waymo’s future. By all accounts, most people in Los Angeles like the driverless cars. LA hasn’t experienced the same fierce objections to Waymo as San Francisco. Most of the time, the company has an incredible ability to coast on good vibes and customer delight. The novelty is powerful, and Waymo’s ability to avoid most dangerous situations, while other autonomous vehicle companies have been less lucky, has helped propel it to the front of the pack in the robotaxi race.

But some residents still feel left out of the technological revolution, and those feelings are laid bare during civil unrest like what’s unfolding in LA. They see the gleaming, futuristic robots rolling down the street, with their spinning sensors and all-seeing cameras, and they ask, Why? Did they consent to taking part in an experiment by Big Tech to see if robots can be trained to be better drivers than humans? Will this serve their communities? They point to the examples of blocked intersections, low-speed collisions with pedestrians or cyclists, or minor traffic infractions, and they ask whether this technology is really as ready as the company claims.

The burning Waymos rankle plenty of people, too, even those who support the cause of the protesters. Liberals, especially, often decry the destruction of property and worry that the images of flaming vehicles fuel the right-wing narrative about “lawless cities” and “radicals” or “paid protesters” facing off with law enforcement officers just trying to do their jobs. And they urge protesters to avoid falling into the trap that the right has set for them.

The burning Waymos rankle plenty of people, too.

But of course, it’s never so simple. If Waymo continues to expand to new cities, it will naturally come into conflict with protests, just as it does with street festivals, sports victories, and other situations in which the destruction of property is occasionally the unintended outcome. And if the company continues to cooperate with law enforcement, it may find itself increasingly at odds with communities that distrust these agents of the state.

“Safety is our highest priority,” Waymo spokesperson Ethan Teicher said in an email. “We removed vehicles from Downtown Los Angeles and will not be serving that specific area for the time being, out of an abundance of caution and with guidance from LAPD.”

The company’s mission is to become the world’s “most trusted driver” by making transportation safer and more accessible. And there are cases when Waymo releasing footage to law enforcement can be helpful, like when one of its vehicles witnesses a hit-and-run. But as the company becomes a bigger part of city life, it will inevitably come into conflict with all the many forces that are currently roiling our country. And that’s something that not even the world’s most trusted driver can avoid.

Source link
#burning #Waymos #image #protests

The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?

After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.

#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast">It’s time to panic about AI safetyWhen the phrase “OpenAI hacked Hugging Face” has more or less entered mainstream culture, you know we have an AI problem. This week, we learned more about exactly how OpenAI’s agent broke out of a sandbox and autonomously traversed the web, including a bunch of other supposedly secure web services, all in the name of cheating on a benchmark tests.The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast

we have an AI problem. This week, we learned more about exactly how OpenAI’s agent broke out of a sandbox and autonomously traversed the web, including a bunch of other supposedly secure web services, all in the name of cheating on a benchmark tests.

The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?

After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.

#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast">It’s time to panic about AI safety

When the phrase “OpenAI hacked Hugging Face” has more or less entered mainstream culture, you know we have an AI problem. This week, we learned more about exactly how OpenAI’s agent broke out of a sandbox and autonomously traversed the web, including a bunch of other supposedly secure web services, all in the name of cheating on a benchmark tests.

The fact that this hack happened is a problem. So is the fact that it took a while for anyone to notice. And the fact that it seems no one is willing or able to do much to stop it. (And lest you think it’s just an OpenAI problem, since we recorded this episode Anthropic acknowledged its models have also hacked a bunch of other companies without either party knowing.) It might all just be a bunch of posturing and hype, but it’s also increasingly clear that the companies building large language models either can’t or won’t put the right guardrails on them. So who will?

After all that, it’s time for Brendan Carr is a Dummy, a bunch of vertical video news, and the smashing success of the Ferrari Luce. People are buying it! If one of them is you, we’d love to hear about it.

#time #panic #safetyAI,OpenAI,Podcasts,Policy,Vergecast
Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI">Anthropic says its own AI models breached three companies during security tests | TechCrunch
Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.







Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did. 

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.


That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.







The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.


When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI

Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI">Anthropic says its own AI models breached three companies during security tests | TechCrunch

Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.

In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.

Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.

Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.

Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.

Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.

Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.

That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.

Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.

In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.

The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.

Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.

Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.

Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)

The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.

OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Anthropic #models #breached #companies #security #tests #TechCrunchAnthropic,OpenAI

Post Comment