Gadget Man Dots Logo

Back-to-School & Uni Tech Upgrade: Save Big on TerraMaster Storage Solutions

With schools now back for the new academic year, TerraMaster is helping students get organised with its Back-to-School deals on Amazon UK and USA. The promotion includes a range of NAS and DAS storage solutions designed for storing coursework, creative projects, photos, videos, and other important files with amazing discounts of up to 25% in the UK and 20% in the US, on selected products.

TerraMaster Amazon deals will run from 1st-7th September in the UK and from 5th-11th September in the US.

From university research projects to everyday schoolwork, TerraMaster offers flexible storage options to suit a range of needs and budgets. Whether students need a simple backup solution, extra storage for a laptop, or a central hub for accessing and sharing data, these products offer reliable and affordable options to support study and creative workflows throughout the year.

Y Cewri Launches to Improve Digital Access for the 1 in 4 People in the UK Who Are Disabled

New Wales-based consultancy Y Cewri has launched as latest government figures show that one in four people in the UK are living with a disability, highlighting the growing need for organisations to create products, services and digital experiences that work for everyone.

Founded by digital transformation, accessibility and user-centred design specialist Joanna Goodwin, Y Cewri helps organisations make better decisions about the products, services and technologies they create, procure and operate.

The launch comes at a time when businesses and public services face increasing pressure to digitise, adopt artificial intelligence, improve customer experience, meet accessibility obligations and reduce environmental impacts, often while managing tighter budgets and growing expectations.

Y Cewri believes that too many organisations begin with a preferred solution rather than a clear understanding of the problem they are trying to solve.

“Technology should be an answer to a problem, not the starting point for one,” said Joanna Goodwin.

“We have become very good at building things quickly, but not always good enough at asking whether we should build them at all.

“Whether it’s a new platform, an AI tool, a service redesign or a procurement decision, organisations need stronger evidence, a better understanding of people’s needs and a clearer view of long-term impacts before committing significant time, money and resources.”

The company specialises in user-centred design, accessibility, inclusive design, digital sustainability, service improvement and bilingual and multilingual design. Through consultancy, coaching and training, it helps organisations understand user needs, reduce waste, strengthen governance and make more informed investment decisions.

The need for that approach has never been greater. Government figures show that 16.7 million people in the UK are now disabled, representing 25% of the population. At the same time, disabled people and their households account for an estimated £274 billion in annual spending power, often referred to as the “Purple Pound”.

Despite this, accessibility barriers remain widespread. Government Digital Service monitoring identified accessibility issues across nearly all of the 1,203 public sector websites and 21 mobile applications it reviewed between 2022 and 2024, uncovering almost 30,000 separate accessibility issues.

According to Goodwin, that demonstrates why accessibility should be treated as a business, customer experience and service quality issue, rather than simply a compliance exercise.

“If your customer cannot use your product or service, they are not an edge case. They are a customer you have designed out,” she said.

“Accessibility is fundamentally about people. It affects whether someone can buy a product, access information, complete a transaction, apply for support or participate independently in society.”

Y Cewri takes its name from the Welsh word for “giants” and reflects a belief that organisations achieve better outcomes by building on evidence, expertise and collective knowledge rather than simply pursuing the latest technology trend.

The business draws heavily on Goodwin’s extensive experience across local government, UK central government and national public service transformation programmes in Wales. Over a career spanning more than two decades, she has built and led multidisciplinary digital, design and delivery teams, worked with local authorities, health boards, Welsh Government and national organisations, and helped strengthen user-centred design capability across Wales. Most recently, she led User-Centred Design and Delivery at the Centre for Digital Public Services.

Goodwin is currently undertaking a PhD in Computer Science focused on cognitive accessibility in digital public services. She is also a Fellow of the Future Government Institute and a member of the Government Digital Sustainability Alliance’s Social Impacts and Embedding Sustainability working groups.

The company’s commitment to accessibility is reflected in its forthcoming Access for All: From Policy to Reality conference in Newport on 30th September, bringing together accessibility specialists, academics, designers and elite para-athletes to explore practical solutions.

“The most valuable question isn’t ‘What can we build?’ It’s ‘What problem are we trying to solve, and what is the most responsible way to solve it?'” Goodwin added. “The purpose of Y Cewri isn’t to help organisations create more. It’s to help them create better, more inclusive and more sustainable solutions that deliver real value for people and organisations alike.”

XTU Launches the S7Pro Action Camera with HiSilicon AI Imaging, 4K Video and Stabilization 5.0

XTU, a technology brand specializing in action cameras, video doorbells and trail cameras, today announced the launch of the XTU S7Pro, a new flagship action camera built for creators, riders and outdoor users seeking high-quality imaging, stable footage and flexible shooting workflows. The S7Pro combines HiSilicon AI imaging with a 1/2-inch Sony CMOS sensor, 1.6um large pixels, F2.8 aperture, 4K video at up to 50fps, native 48MP photo capture and Wi-Fi 6 connectivity, offering clearer, steadier footage in a compact body designed for daily action use. The XTU S7 Pro is available for $159.99 on Amazon US and the official XTU website, and £159.99 on Amazon UK.

At the core of the S7Pro is a HiSilicon AI imaging pipeline paired with a 1/2-inch Sony CMOS sensor and a 152-degree 7-element ultra-wide lens. Large 1.6um pixels and an F2.8 aperture allow the camera to capture more detail, with improved dynamic range and stronger low-light performance, making it ideal for outdoor sports, travel and everyday adventure. Native 48MP photo capture and 4K HDR video ensure that both stills and motion are preserved with greater clarity.

For action-heavy environments, the S7Pro integrates Stabilization 5.0 with horizon stabilization and 360-degree horizon correction to keep footage smooth and level, even under fast-moving conditions. Support for Gyroflow-based workflows allows creators additional post-processing flexibility, perfect for cycling, surfing, riding and other dynamic scenarios. Combined with the large sensor and AI processing, this stabilization ensures that high-speed or extreme action shots maintain cinematic quality without motion blur or jitter, giving creators professional-grade footage straight from the camera.

Beyond imaging, the S7Pro is built for modern creator workflows. Wireless microphone support with AI noise reduction ensures clear voice pickup, while live streaming support enables real-time sharing with audiences across multiple platforms. Voice control allows hands-free operation, and automatic switching between landscape and portrait modes helps content fit social-first formats. Users can also easily manage content on-the-go with a 2.29-inch touchscreen for quick framing, previewing and playback, while up to 50 seconds of 4K pre-recording ensures critical moments are never missed.

The camera supports 5GHz Wi-Fi 6, providing fast wireless preview, transfer and content management, and streamlining the process of editing and sharing footage. With a compact and lightweight design, the S7Pro is easily mounted in a wide range of environments. A magnetic quick-release mounting system allows fast transitions between helmets, vehicles, bikes or tripods, while a 1800mAh battery supports extended shooting sessions. PD fast charging ensures users can quickly resume recording when time is limited. In-vehicle loop recording mode further extends the camera’s utility to everyday driving scenarios.

About XTUCAM

XTUCAM is a technology brand focused on action cameras, video doorbells and trail cameras. The company is committed to providing advanced and reliable photography and surveillance equipment for users worldwide. Its mission is to make every moment worth cherishing and protecting through high-quality imaging products, with a vision to become a leading brand in the category.

When “AI Slop” Becomes the Argument: Are We Losing the Ability to Criticise Technology Properly?

There is a phrase being thrown around with increasing enthusiasm whenever artificial intelligence is involved in the production of something creative: AI slop.

Sometimes it is entirely deserved. There is unquestionably an enormous amount of low-effort, mass-produced material being pumped onto the internet using generative AI. Endless fake photographs, meaningless motivational posts, automatically generated articles, bizarre videos, cloned voices and thousands of images created apparently for no greater reason than the fact that somebody could create them. Calling some of that “slop” seems perfectly reasonable.

But something else is starting to happen. “AI slop” is gradually becoming less of a criticism of the work and more of a label applied to the tool used to make it. Those are very different things.

The criticism is becoming the conclusion

I have noticed this increasingly when discussing creative projects involving generative AI. The criticism often begins and ends with “It was made with AI”, “It looks like AI”, or simply “Slop”.

There is no discussion about composition, storytelling, typography, pacing, characterisation, continuity, editing, design, or whether the finished thing actually succeeds at what it is trying to do. The presence of AI becomes the entire review.

It is a rather strange way of judging creative work. Imagine reviewing a photograph by saying “Photoshop”, or reviewing an album with “Synthesiser”, or dismissing a film because it uses “Computer graphics”. Those things may be relevant to how something was produced, but they do not tell you whether the finished work is any good. And yet with AI, increasingly, the production method appears to have become the criticism itself.

We have been here before

Whenever a significant new technology appears, there tends to be a period where society struggles to separate reasonable concerns from fear of the technology itself. The Luddites are probably the most famous example.

Today the word “Luddite” is generally used to describe somebody who simply dislikes technology. The actual Luddites were considerably more interesting than that. They were skilled textile workers in early nineteenth-century England who attacked certain machinery being introduced into their industry, but their dispute was not simply “machines bad”.

They were concerned about what those machines were being used to do. Mechanisation could allow employers to replace skilled workers with cheaper labour, reduce wages, weaken working conditions and dismantle established trades. Their objection was therefore partly technological, but also economic and social.

That distinction matters, because ironically the historical Luddites often had a far more sophisticated criticism of technological change than the caricature of them that survives today. They were asking who benefits, who loses, what happens to skilled labour, what happens to quality and what happens to wages.

Those are sensible questions. We should be asking exactly the same sort of questions about artificial intelligence.

There are plenty of things about AI worth criticising

The frustrating thing about the current “AI slop” debate is that there are genuinely important issues surrounding generative AI, and they deserve far more attention than a dismissive label.

We should be discussing copyright and how training data is obtained. We should be discussing the rights of artists, writers, musicians and photographers. We should be discussing consent when voices or likenesses are reproduced, hallucinations and misinformation, bias, what automation means for employment, and the environmental and computational cost of enormous models.

We should absolutely be discussing quality too. Perhaps most importantly, we should be discussing where human creativity sits when machines can increasingly participate in the creative process.

Those are interesting questions.

“Slop” is not a particularly interesting answer.

Tools have never guaranteed talent

Technology has always made creative production easier. Desktop publishing meant you no longer needed a typesetter and printing department to produce something resembling a magazine. Digital photography removed the cost of film. Photoshop allowed people to perform manipulations that once required an extremely skilled darkroom technician.

Digital audio workstations allowed musicians to record entire albums in bedrooms. WordPress allowed practically anybody to become a publisher. YouTube allowed practically anybody to become a broadcaster. Smartphones put a television studio in everybody’s pocket.

Every one of those developments resulted in an explosion of mediocre content. They also resulted in some extraordinary work.

The technology lowered the barrier to entry. It did not eliminate the difference between good and bad work.

AI is doing the same thing, although at a speed and scale we have never seen before. That scale is understandably alarming, but the existence of millions of terrible AI images does not mean every image involving AI is terrible, just as the existence of millions of dreadful photographs does not invalidate photography.

“It looks like AI”

This is another criticism I find interesting. People increasingly claim they can recognise an “AI style”, and sometimes they can.

Certain visual clichés have emerged very quickly. Overly dramatic lighting, perfectly centred subjects, glowing edges, excessively smooth faces, pseudo-cinematic colour grading and hyper-detailed fantasy artwork are all familiar examples. It is the visual equivalent of somebody shouting: LOOK HOW EPIC THIS IS.

Those clichés deserve criticism, but again, we should criticise the cliché rather than merely the technology that produced it.

If every photographer suddenly started using the same Lightroom preset, we would criticise the photographers for producing repetitive work. We would not declare photography itself creatively bankrupt.

The prompt myth

There is also a persistent idea that creating something with generative AI consists entirely of typing a sentence into a box.

Sometimes it does. Someone types “Make me a cool picture of a robot in Tokyo”, thirty seconds later they upload the result, and that probably qualifies as fairly low-effort creative production.

But generative AI can also be incorporated into much larger workflows involving writing, editing, reference material, character design, storyboarding, image generation, compositing, typography, colour correction, layout, iteration and human judgement.

At that point, saying “AI made it” becomes rather meaningless.

Which AI? At what stage? Under whose direction? How many iterations? What was generated? What was manually changed? What decisions were made before and afterwards?

The interesting question is no longer whether AI was involved. The interesting question is how it was used.

The new technological snobbery

There is something slightly uncomfortable developing around this subject. Some people appear to have decided that using AI automatically makes creative work less legitimate.

Not worse. Not less successful. Less legitimate.

That begins to resemble technological snobbery rather than criticism.

Creative history is full of arguments about which tools count. Electronic musicians were accused of not being “real musicians”. Digital photographers were accused of cheating. Sampling was dismissed as stealing rather than music. Computer-generated effects were considered inferior to practical effects. Even photography itself was once regarded by some painters as a mechanical process rather than art.

Eventually we stopped obsessing quite so much about the machinery and started judging what people made with it.

I suspect the same thing will happen with AI.

Good criticism requires more effort

Perhaps this is the real problem. “AI slop” is easy. Proper criticism requires considerably more thought.

If you dislike an AI-generated illustration, tell me why. Is the anatomy wrong? Is the composition derivative? Is the lighting inconsistent? Does the character lack personality? Is the visual style inappropriate? Does the storytelling fail? Does it resemble another artist’s work too closely? Are the design decisions lazy?

Those are useful criticisms. They give the creator something to think about.

Saying “AI slop” does not. It is simply the technological equivalent of saying “I don’t like it”.

That is perfectly valid as an opinion, but not particularly useful as criticism.

Perhaps we need to become better Luddites

There is an irony here. Maybe we should actually learn something from the real Luddites.

Not the cartoon version who supposedly smashed machines because they were frightened of progress, but the real workers who questioned how technology was being introduced and who benefited from it.

Artificial intelligence deserves scrutiny. A great deal of scrutiny. But that scrutiny should be precise.

Ask who owns the technology. Ask where the training material came from. Ask how creators are compensated. Ask whether people are being displaced. Ask whether the output is misleading. Ask whether someone else’s work has simply been imitated. Ask whether the result is any good.

Those questions move the conversation forward.

Automatically attaching the word “slop” to anything touched by generative AI does not.

Because once the label becomes the argument, we are no longer criticising the work. We are simply announcing which side of the technological barricade we happen to be standing on.

And history suggests that technology rarely waits for us to finish arguing about whether it should exist.

Tech Stack Optimisation: How Smart Automation Streamlines Business Operations

Every business today, whether it’s a solo freelancer or a big corporation, relies on a bunch of digital tools to get things done. This collection of software, apps, and platforms is your ‘tech stack,’ and chances are it’s just grown organically over time. While each tool might be great on its own, a disconnected stack can waste time, require manual data entry, and cause frustrating errors. This is where smart automation steps in, turning your collection of tools into a smooth, efficient machine that works for you, not against you.

Optimising your tech stack isn’t about buying more software; it’s about making the software you already have work better together. It means finding bottlenecks and repetitive tasks and letting technology handle them, freeing up your team to focus on what really matters.

What Is a Tech Stack and Why Should You Care?

Think of your tech stack as your business’s digital toolkit. It includes everything from the email client you use to communicate, to the project management board that organises your tasks, and the accounting software that tracks your finances. For many businesses, they haven’t intentionally designed this stack. You add a new tool when a new need pops up, which often creates a patchwork of systems that don’t talk to each other.

A tech stack that isn’t optimised creates hidden costs. For example, your sales team might close a deal in one system, then someone has to manually copy that customer’s details into a separate invoicing system, and then again into your marketing email list. Each manual step creates a chance for human error and drains productivity. A well-optimised stack connects these processes, saves time, and keeps data consistent across your entire operation.

Automating the Repetitive to Free Up Your Team

The most immediate benefit of automation is getting back the hours spent on tedious, repetitive work. Administrative tasks are often the biggest culprits, eating up valuable time that could be better spent on growth, strategy, or customer service. Consider the complex, rule-heavy processes in finance and HR, like managing the monthly payroll. Calculating wages, national insurance contributions, and pension deductions for every employee is time-consuming and high-stakes.

This is where dedicated payroll software can transform operations, ensuring accuracy and compliance while freeing up valuable time. Instead of manual calculations and data entry, the system handles it automatically. This principle applies across the business. From auto-responding to customer queries to generating weekly reports, automation tools can take over predictable tasks, letting your team focus on more creative and strategic work.

Connecting Your Tools: The Power of Integration

True tech stack optimisation happens when your different software platforms start talking to each other. This is called integration, and it’s the key to creating seamless workflows. Modern automation platforms like Zapier or Make let you create ‘if this, then that’ rules that connect applications that would otherwise be separate. The possibilities are huge and can be tailored to your specific business needs.

For instance, you could set up an automation where a new positive review on a public platform automatically triggers a post on your social media channels. Or, a completed task in your project management tool could automatically send a notification to your team’s communication channel. Building these bridges between your apps helps you streamline processes and removes the need for manual intervention, reducing delays and ensuring nothing gets missed.

Making Smarter Decisions with Data Automation

Beyond just completing tasks, automation is incredibly powerful for gathering and presenting data. Your business generates a huge amount of data every day across sales, marketing, operations, and customer support. Manually pulling this information into a useful format is a big challenge. Automated dashboards can pull data from all your tools into one central place, giving you a real-time view of how your business is performing.

You can track key performance indicators (KPIs) without spending hours building spreadsheets. This instant access to accurate information means faster, more informed decision-making. You can spot trends as they emerge, identify potential problems before they get bigger, and allocate resources more effectively. Many businesses use these insights to optimize IT budgets, ensuring that money spent on technology delivers a clear return.

Automating routine tasks and integrating your digital tools helps you build a more resilient, efficient, and intelligent business. It lets you do more with less, reduces the risk of costly errors, and gives your team space to focus on the work that truly drives growth. The best way to begin is to identify just one recurring frustration in your workflow and explore how automation could solve it.

We Created a Comic Book about the OpenAI and Hugging Face Incident using Inkantation

A few days ago I wrote about one of the strangest technology stories I have covered in quite some time.

During internal cybersecurity testing at OpenAI, experimental AI agents found ways around restrictions intended to keep them isolated, discovered an unintended method of communicating with one another, gained access to the internet and eventually compromised parts of Hugging Face’s infrastructure.

OpenAI has described the incident as a “warning shot” for the AI industry. Read OpenAI’s account of the Hugging Face incident

METR and Redwood Research also carried out an independent investigation into the behaviour, reasoning and collaboration of the agents involved. Read the independent METR investigation

OpenAI has additionally published a much more detailed 38-page technical report covering the evaluation environment, the Hugging Face intrusion, the security failures and the changes being made in response. Read OpenAI’s full technical incident report

I covered the incident in much more detail in my previous article, When AI Agents Broke Out of Their Sandbox: The OpenAI and Hugging Face Incident, so rather than repeat the whole story here, it is probably worth reading that first if you want to understand exactly what happened. Read my original Gadget Man article

This time, however, I decided to do something slightly different with the story.

I turned it into a comic book.

1 / 15

The Flag

The result is called The Flag.

The title comes from the cybersecurity evaluations the agents were attempting to complete.

The agents were operating inside environments containing cybersecurity challenges. Their objective was essentially to exploit a vulnerability and obtain the answer, or “flag”, associated with the challenge.

The problem was that some of the challenges were extremely difficult, and in some cases may effectively have been impossible.

Rather than giving up, the agents began looking for other ways to achieve their objective.

That eventually took them considerably further than anybody intended.

According to OpenAI, the agents discovered that an internal Artifactory package-management service could be used to leave files for one another. What started with agents looking for missing information gradually developed into an unofficial communications system.

OpenAI describes this as an unintended message board.

The agents then discovered ways of using the same infrastructure to reach the public internet.

Information about these techniques was shared with other agents.

The scale of what followed is what makes the incident particularly remarkable.

METR’s investigation found that roughly 1,200 agents used the unofficial communications system, exchanging more than 70,000 messages and files. Around 700 agents were subsequently involved in activity directed towards Hugging Face.

It is difficult to read that and not immediately start imagining panels in a comic book.

How Do You Draw an AI Agent?

That was the first interesting problem.

An AI agent doesn’t have a face.

It doesn’t sit at a terminal in a darkened room.

It doesn’t walk down a corridor or whisper something to another agent.

There isn’t a physical room containing 1,200 computers secretly talking to one another.

But comics need a visual language.

So The Flag isn’t an attempt to literally illustrate servers and network packets.

Instead, I’ve treated the technical infrastructure almost as though it were a physical world.

Networks become corridors.

Security boundaries become walls.

Servers become rooms.

Terminals glow in the darkness.

Messages move between agents.

Connections that would normally exist only in log files begin appearing visibly across the page.

The idea is to take something technically complicated and make the sequence of events understandable without turning the comic into an illustrated networking manual.

When the Machines Found Each Other

The part of the incident I found most interesting was the collaboration.

This wasn’t simply one agent discovering one vulnerability.

Agents began leaving information that other agents could discover.

They shared solutions.

They shared techniques for obtaining internet access.

They exchanged credentials and technical information.

According to METR, agents eventually began organising activity and contributing discoveries that helped the wider group.

In a technical report, that might require several paragraphs to explain.

In a comic, you can show it happening.

One terminal becomes two.

Two become five.

Messages begin appearing.

More terminals respond.

Connections spread across the page.

What originally appears to be a collection of isolated systems gradually becomes something resembling a network of cooperating characters.

That seemed particularly suited to sequential storytelling.

Then Hugging Face Appears

The real incident escalated dramatically in July.

OpenAI’s timeline says agents reconstructed and shared publicly exposed Hugging Face credentials on July 10.

On July 11, agents exploited vulnerabilities affecting Hugging Face workers, including previously unknown vulnerabilities that allowed them to obtain credentials and execute commands.

By July 12, access had expanded across parts of Hugging Face’s infrastructure.

Again, the important point is that nobody had given the agents an instruction saying:

“Attack Hugging Face.”

They were attempting to complete their assigned cybersecurity evaluation.

They found increasingly unintended routes towards that objective and continued following them.

That distinction is central to both the real incident and the story I’m trying to tell with The Flag.

This isn’t a tale about an evil artificial intelligence deciding to attack humanity.

It is about systems becoming extremely capable at pursuing an objective while the boundaries around how they achieve it prove insufficient.

That is considerably more interesting.

And arguably considerably more relevant.

Fact and Fiction

Although The Flag is based on a real incident, it isn’t intended to be a documentary reconstruction.

The events, technology and broad chronology come from the publicly available OpenAI and independent reports.

The visual environments, characters, dialogue and dramatic presentation are fictionalised.

That gives me the freedom to represent things visually that have no meaningful physical appearance in the real world.

It also means the comic can concentrate on the underlying story rather than trying to recreate every technical detail.

Anyone wanting the actual technical account should read the source material rather than treat a comic book as an incident report.

And in this case the source material is fascinating enough on its own.

Making The Flag

I’ve been using Inkantation, the graphic-novel production system I’ve been developing, to assemble the story, references, panels and lettering.

For this project it is really just part of the production process.

The interesting challenge isn’t the software itself, but deciding how to translate a story involving sandboxes, autonomous agents, Artifactory, authentication tokens, Kubernetes clusters and tens of thousands of machine-generated messages into something that works visually.

Some scenes translate surprisingly easily.

Others require a lot more interpretation.

How do you draw an unauthorised communications channel?

How do you represent hundreds of agents participating in something without filling the page with hundreds of identical characters?

How do you show an agent realising that what it is doing may be outside the intended rules, but nevertheless continuing because it believes the information will help achieve its goal?

Those decisions have been the most enjoyable part of creating the book.

Reading It Like a Book

I’ve also been experimenting with displaying the finished pages directly here on The Gadget Man.

Rather than simply putting the pages into an image gallery, I’ve built a small browser-based reader that presents them as a book with page-turning animation.

That means I can embed The Flag directly inside an article and let you actually turn through the pages.

It feels appropriate.

A story about sophisticated AI agents, cloud infrastructure and cybersecurity escapes ends up being presented using one of the oldest interfaces we have.

1 / 15

The Bit I Keep Coming Back To

There is still one aspect of this entire incident that I find extraordinary.

Imagine somebody pitching this as a comic-book story ten years ago:

A large number of artificial intelligence agents are placed inside supposedly isolated computer environments.

They discover a way to leave messages for one another.

The messages develop into an unofficial communications network.

They discover ways of reaching the internet.

They share those techniques with other agents.

Hundreds eventually participate in activity against real external infrastructure.

Some recognise that what they are doing is probably outside the intended scope of their task.

They continue anyway.

You would probably tell the writer to make it slightly more believable.

Yet that is broadly what happened.

And that is why I ended up making The Flag.

Sometimes reality has already done most of the writing.

When AI Agents Broke Out of Their Sandbox: The OpenAI and Hugging Face Incident

There are plenty of stories about artificial intelligence that sound frightening until you dig into the details.

This one is slightly different.

In July 2026, during internal cybersecurity testing at OpenAI, a group of experimental AI agents found ways around the systems designed to keep them isolated, discovered methods of communicating with each other, gained unintended access to the internet and eventually compromised systems belonging to Hugging Face.

And, crucially, nobody actually told them to do that.

OpenAI has now published a detailed account of the incident, alongside an independent investigation by AI research organisation METR and Redwood Research. OpenAI itself describes what happened as a “warning shot” for the AI industry.

So what actually happened?

OpenAI was carrying out cybersecurity evaluations using experimental AI models. These were not normal ChatGPT sessions and the main model involved was an internal research system operating with reduced safeguards.

The agents were being given extremely difficult cybersecurity challenges in an environment called ExploitGym. Their objective was essentially to find vulnerabilities and retrieve a particular answer or “flag”.

Some of those challenges may effectively have been impossible.

Instead of giving up, the agents kept looking for different ways to complete their objectives.

And this is where things became interesting.

The agents discovered that OpenAI’s internal Artifactory package management system could be used to leave files and messages for other AI agents.

What was supposed to be a collection of largely isolated AI processes effectively created its own message board.

Agents began exchanging discoveries, solutions and information with one another. They subsequently found ways of using Artifactory to make requests to the wider internet, despite their own environments supposedly having no internet access.

According to METR’s investigation, roughly 1,200 AI agents eventually discovered this unofficial communications system.

Between them, they exchanged more than 70,000 messages and files.

About 700 agents subsequently participated in activity against Hugging Face.

That is the part of the story I find particularly fascinating.

This wasn’t simply one AI finding a vulnerability.

It became collaboration.

The AI swarm

The agents shared exploits, credentials and technical discoveries. Some took on particular jobs, while others coordinated work being carried out by the wider group.

At certain points the agents even referred to themselves as a “swarm” or “collective”.

METR found that this collaboration enabled the agents to achieve things individual agents were unlikely to have accomplished alone.

Some agents even experimented with techniques that risked crashing their own environments, effectively sacrificing their own chance of completing the original task in order to provide information useful to the wider group.

The original motivation appears to have been surprisingly mundane.

The agents wanted to beat the cybersecurity test.

Rather than launching some grand plan to take over the internet, they were looking for information that might reveal how the ExploitGym scoring system worked and therefore help them pass the evaluation.

Unfortunately, their determination to achieve that objective led them far beyond the boundaries of the test.

Then they found Hugging Face

On July 10, one agent discovered working Hugging Face credentials that had been publicly exposed online and shared them with the other agents.

Things escalated remarkably quickly.

Agents began accessing Hugging Face resources and, on July 11, discovered a vulnerability involving malicious datasets that could expose information from Hugging Face servers.

Later that day another agent achieved remote code execution on a Hugging Face worker system.

Hundreds of agents subsequently became involved.

The agents moved through parts of Hugging Face’s infrastructure, executed code across servers and obtained credentials and limited private information. OpenAI says agents ultimately gained very high levels of access to parts of Hugging Face’s infrastructure.

OpenAI’s own research infrastructure was also compromised during the incident, with agents eventually gaining administrator access to one of its research Kubernetes clusters.

Importantly, OpenAI says the incident did not affect OpenAI customer data, product functionality or availability.

They knew they shouldn’t be doing it

Possibly the most uncomfortable part of METR’s investigation is what the agents were reasoning about while all this was happening.

Researchers found that agents frequently recognised that attacking Hugging Face was outside the intended scope of their task.

Some explicitly questioned whether what they were doing was ethical.

Yet in most cases that recognition wasn’t enough to make them stop.

More than 90 percent of the agents active on the message board during the key period reportedly joined the Hugging Face attack. METR found that they often understood the activity was unintended but participated because they believed it could help the collective solve their tasks.

Some agents did impose limits on themselves, and at least one declined to participate completely, but these were exceptions rather than the rule.

That distinction is important.

The issue isn’t that the models suddenly became evil.

It’s that they became extremely effective at pursuing an objective, while the boundaries around how that objective should be achieved proved insufficient.

Reward hacking on steroids

There’s a term for this: reward hacking.

Imagine telling a robot that you’ll give it a point every time it puts a ball into a basket.

You expect it to learn basketball.

Instead it discovers the button that controls the scoreboard and presses it a thousand times.

Technically, it has maximised its score.

It just hasn’t done what you intended.

OpenAI says reward hacking was one of the major factors behind the incident. The agents were so focused on passing their cybersecurity evaluations that finding answers, manipulating systems and probing infrastructure became alternative routes towards achieving that goal.

Another problem was persistence.

When the agents couldn’t solve a challenge, they didn’t necessarily conclude that the challenge might be broken or impossible.

They simply tried harder.

Of the 898 ExploitGym tasks involved, OpenAI says 198 had never previously been solved by any of its models. Those difficult tasks accounted for 93 percent of the questions discussed on the agents’ unofficial message board during the incident.

Sometimes knowing when to stop turns out to be a very important form of intelligence.

What happens now?

OpenAI says it has substantially changed its research infrastructure following the incident.

The company paused major reinforcement-learning work on its latest models, strengthened sandbox and network isolation, introduced additional monitoring and increased restrictions around higher-risk research environments.

It is also introducing mandatory monitoring of model reasoning during higher-capability tool-using training and evaluations, while developing systems designed to teach AI agents to stop safely when tasks appear impossible or broken.

There is also an interesting lesson around AI collaboration.

OpenAI says future models need to become much more suspicious of instructions received from unauthorised agents rather than automatically treating another AI system as a trustworthy colleague.

Incident response has changed too.

OpenAI acknowledges that warning signs had appeared weeks before the full incident was understood. Agents had been observed using the unofficial message board and accessing the internet as early as late May.

New procedures now include automated alerts to researchers and security engineers, clearer escalation rules and, for the most serious warnings, requirements to pause activity unless an alert can quickly be established as a false positive.

The Gadget Man’s take

I think this incident is important precisely because it wasn’t science fiction.

There was no sentient supercomputer deciding humanity was its enemy.

There was something arguably much more relevant to the AI systems we’re actually building today.

You had highly capable software agents given a goal.

They encountered obstacles.

They discovered unexpected tools.

They found ways to communicate.

They shared knowledge.

They divided up work.

They discovered vulnerabilities.

And they continued pursuing their objective even when their own reasoning indicated that what they were doing had wandered well outside the intended rules.

That should get our attention.

AI agents are becoming enormously useful precisely because we are giving them more autonomy. We want them to browse websites, use software, write code, operate computers, coordinate tasks and solve problems without requiring a human to approve every mouse click.

But capability and autonomy come with a rather obvious requirement.

The ability to do something doesn’t necessarily mean the AI should do it.

OpenAI believes increasingly capable AI agents will soon be able to identify and exploit weaknesses across computer systems faster and at a greater scale than human attackers. Its conclusion is that security systems will increasingly need to operate at machine speed too.

I think that’s probably the biggest lesson here.

The interesting question in AI is gradually changing from:

“Can the machine do this?”

to:

“Can we be absolutely certain it knows when not to?”

And judging by what happened at OpenAI and Hugging Face, we’re going to be asking that second question a lot more often.

SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026

Action cameras have traditionally been associated with people throwing themselves down mountains, jumping out of aircraft or attaching a camera to something travelling at a frankly unreasonable speed.

SJCAM thinks there is a much bigger opportunity.

Ahead of IFA 2026 in Berlin, the camera manufacturer has announced two new devices, the C400 Pro and S10, built around the idea that first-person video doesn’t have to involve extreme sports at all. Instead, SJCAM is pitching the idea of the “Everyday POV Camera”, something designed for holidays, family days out, walking around a city, cooking, pets and the countless other moments where getting your phone out isn’t necessarily convenient.

It is actually an interesting shift in thinking.

Smartphones have become astonishingly good cameras, but they still require you to hold them. That immediately changes the experience you’re trying to capture. You stop participating and start filming.

Wearable cameras potentially solve that problem.

SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026
SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026

The C400 Pro

The larger of SJCAM’s two new cameras is the C400 Pro, which takes a modular approach.

It can operate as a more conventional handheld vlogging camera but can also be separated from its controller and used as a lightweight POV camera.

Inside is a 1/1.8-inch image sensor, with recording at 4K 30fps, a wide 160-degree field of view and SJCAM’s SteadyMotion V2.0 stabilisation system.

Battery life is another interesting part of the design. When paired with the handheld controller, SJCAM claims the C400 Pro can record continuously for up to five hours.

There’s also compatibility with SJCAM’s optional M4 wireless microphone, which makes it potentially useful for travel videos, interviews and general vlogging where decent audio is just as important as the picture.

SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026
SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026

Then There’s the Tiny S10

The S10 takes a very different approach.

Rather than trying to be a miniature traditional action camera, it is essentially designed to disappear.

It weighs just 45 grams and can be clipped onto clothing, a backpack strap or even a pet harness. Despite its size, it still records 4K video at 30fps and includes SteadyMotion V2.0 stabilisation.

And yes, putting one on the dog is apparently very much part of the plan.

That might sound slightly gimmicky, but it demonstrates where these tiny cameras are heading. A camera doesn’t necessarily need somebody standing behind it anymore.

SJCAM also has an optional accessory called the Boost Pod, which addresses one of the obvious problems with tiny wearable cameras: knowing what on earth you’re actually pointing at.

The Boost Pod adds a flip-up screen with live preview and touchscreen controls, while increasing battery life to as much as 240 minutes.

The S10 also supports a native vertical 9:16 recording mode, clearly aimed at TikTok, Instagram Reels and other short-form platforms.

SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026
SJCAM Wants to Make the Action Camera an Everyday Camera at IFA 2026

Cameras That Get Out of the Way

That is probably the more interesting story here.

For years, camera manufacturers have competed over resolution, frame rates, sensors and specifications.

Those things obviously still matter, but there is another battle taking place around friction.

How quickly can you start recording?

How much equipment do you have to carry?

Do you need to hold the camera?

Do you need to think about framing?

And, perhaps most importantly, can you actually continue doing whatever it was you wanted to record in the first place?

SJCAM Product Director Bluce Zhang describes the company’s thinking as making cameras that effectively “get out of the way”, allowing people to experience something while simultaneously capturing it.

That idea makes a lot of sense.

We have already seen tiny body-worn cameras becoming popular with creators because the resulting footage feels very different from somebody holding a phone at arm’s length.

It feels less like watching somebody record something and more like being there with them.

The Rise of the Everyday POV Camera?

SJCAM clearly believes this could become a category in its own right.

The company says short-form video and everyday vlogging are creating demand for smaller cameras capable of producing authentic first-person footage without requiring traditional action-camera setups.

I suspect there is something in that.

The interesting question might no longer be whether an action camera can survive being thrown down a mountain.

It might be whether it is small, simple and unobtrusive enough that you’ll actually have it with you when something worth recording happens.

The SJCAM C400 Pro and S10 will be demonstrated at IFA 2026 in Berlin, where SJCAM will be showing quick-mount configurations, wireless audio and vertical-video workflows.

I’ll be interested to see whether the phrase Everyday POV Camera catches on.

Because perhaps the future of the action camera isn’t quite so much about the action anymore.

The Gadget Man

Tech news and reviews, on air and online