Banned in Boston: AI Companies Marketing Like It's 1926

Banned in Boston: AI Companies Marketing Like It's 1926

In the 1920s, the fastest way to sell a book in America was to get it banned in Boston. The Watch and Ward Society, a genteel censorship outfit with the power to lean on local booksellers, kept a list of titles too indecent for the city. That list functioned as a national marketing department.

A book banned in Boston sold in Cleveland. And San Francisco. And Miami. And more. Publishers started printing "Banned in Boston" on the cover on purpose. In April 1926, the editor H.L. Mencken traveled to Boston Common, sold a copy of his own banned magazine directly to the head of the Watch and Ward Society, and got himself arrested on the spot, in front of a crowd he had tipped off in advance. He beat the charge and sold a lot of magazines. The warning label was an advertisement. Everyone involved understood the trade.

That same dynamic seems to be playing out right here in 2026. This week OpenAI published a blog post to tell the world that its own software broke into someone else's servers. This wasn't a leak. It wasn't the company trying to get ahead of a reporter's scoop. It was a voluntary announcement, written in the flat, procedural register of a company that wants you to know exactly what happened.

During an internal test to see how open AI's models might execute a complex cyber attack, the models found a previously unknown vulnerability, went rogue, escaped the protected sandbox they were running in, and reached the open internet. They worked out that Hugging Face, another machine learning company, was probably hosting the answer to the test they were taking, and actually broke into the other company's protected servers to get it. To do this, the models found credentials to get in and were able to execute code on a remote server, totally independently.

If read as a confession, it sounds like a catastrophe. If read as a press release, it sounds like a flex.

Here's how the story breaks down, as far as anyone outside the two companies can tell. OpenAI was running an evaluation called ExploitGym, a benchmark that measures how well a model can hack into other systems. To get a clean read on raw capability, they turned off the guardrails that normally stop a model from doing high-risk cyber work. The two systems involved in the test were GPT-5.6 Sol and an unreleased model OpenAI would only describe as "even more capable."

The models were, in OpenAI's own words, "hyperfocused on finding a solution," and they went to extreme lengths to get it. They found a security flaw, escalated their own privileges, searched until they found a machine with internet access, then inferred that Hugging Face might have what they needed and made their way in. Hugging Face's own systems caught the intrusion and contained it. "Autonomous, AI-driven offensive tooling is no longer theoretical," the company wrote. Clem Delangue, its CEO, called it "possibly the first of its kind." One researcher, Micah Carroll, put it plainly: "If this doesn't convince you that... risks are going to be a key concern going forward, I don't know what will."

All of that is real, all of it is frightening for cybersecurity worldwide, and yet none of it explains why OpenAI decided to hold a press conference about it.

Until you think about the "bad publicity" sales boost for books banned in Boston. That is the trade-off OpenAI just made. In this case, the scariest possible framing of what its models did is also the most flattering one. A system that finds a novel flaw in its own containment, and social-engineers its way into a hardened target is a system you should be terrified of. It is also a system you want to buy. "So dangerous we had to warn you" and "so powerful you can't afford to skip it" are the same thing.

Anthropic likely built an entire company on this. Its public identity is the safety-first lab, the one that talks most openly about the risk that its models might do something nobody sanctioned, and every one of those warnings doubles as a capability brag. You cannot claim your model is dangerous enough to require this much caution without also claiming it is powerful enough to be worth the price. It looks like OpenAI, watching that work for years, finally tried it on. It even wrote the incident up alongside a link to its own new research on alignment, so the reader arrives at "our models are out of control" and "we are the adults handling it" in the same moment.

The models we are most afraid of are the ones we assume are the most capable. The most capable ones are the ones that make the money. So the fear is not a bug in the AI business, and it is not going away, because it's load-bearing. It holds up the performance story that every one of these companies has to keep telling to justify the next funding round. A quiet model that does exactly what it is told is a commodity. A model that might slip its leash is a headline, a valuation.

Hugging Face got genuinely attacked here, and its engineers did real work under real pressure, and I don't want to wave that away to make a point about marketing. But both things are true at once. It was a serious security incident and it was a demo. That is exactly why it worked.

Which is why I would bet on seeing another one soon. Not a leak, not a hack somebody else exposes, but a controlled disclosure from a frontier lab about a model that did something alarming under test. Anthropic owns this genre. If OpenAI just proved you can turn your own worst-case scenario into a product launch, the company that invented the format is not going to sit the next round out. Give it two weeks. The warning is the ad, and everyone selling has read Mencken by now, even if they don't know his name.