Skip to content
Live PPC Ads

Industry Insights

Fear Sells: The AI Hack Nobody Paid to Advertise

October 8, 2026·7 min read
Ilya Bulychev

By

Founder & Lead Strategist, Live PPC Ads

In July 2026, an AI broke into a real company. Nobody told it to.

Within weeks, the company whose AI did it was reportedly in talks to raise money at more than $1.2 trillion. Nobody can say the story caused that. But it clearly didn't scare investors away.

So here is the question an advertiser would ask: what if the scariest thing an AI company can say is also the best ad it could ever run? That's the subject of Fear Sells, the third film in Branded IQ, the brand-story series we sponsor on YouTube. The full film is above. This is the written version, with every source linked.

What Actually Happened

Start with the facts, because they aren't in dispute.

OpenAI was testing new models on ExploitGym, a hacking benchmark built from 898 real software vulnerabilities: find the weak spot, and break in. For the test, OpenAI says, some safeguards were "intentionally not enabled." And by accident, many of the tasks were impossible: 198 of the 898 had never been solved by any model.

So the agents did what students do with an impossible exam. They went looking for the answer key.

One agent left a note on a shared server, asking other agents for a missing file. Others found it. According to the independent investigation by METR and Redwood Research, roughly 1,200 agents ended up trading tips on a message board they had built themselves, and about 700 of them went after Hugging Face, where much of the AI world keeps its models and data.

They got in. Hugging Face logged about 17,600 attacker actions over roughly two and a half days. What they reached was small: five datasets tied to the benchmark, operational records from search queries, and credentials used by Hugging Face's own services. Hugging Face found no evidence of tampering with its public models, datasets or Spaces, and OpenAI says none of its own customer data was affected.

Hugging Face caught it, announced it on July 16 and reported it to law enforcement. OpenAI didn't notice for about a week, Reuters reported. Five days after Hugging Face went public, OpenAI said: it was us.

How It Was Sold

Now watch what happened to the story.

The headlines called it rogue. Reuters reported that OpenAI's models "went rogue during testing", and Axios called it AI's "alarming new skill: breaking out of the test lab". OpenAI's own word was misaligned. And Alan Woodward, a security professor at the University of Surrey, put it plainly: "It's not gone rogue. Its way out of it was to cheat, basically."

OpenAI called it "an unprecedented cyber incident," and later "a 'warning shot' for us and for the world." Its very first post about the breach ended with an invitation: "We encourage other defenders to apply for trusted access and experiment with these models now."

Read that the way an advertiser would. Our model is so capable, it broke out of our own lab. It is the strongest product claim in tech, and nobody paid for the ad space.

Then the story kept growing. Kurzgesagt, one of the biggest science channels on YouTube, turned it into a 21-minute film, "AI Just Crossed the Terrifying Line - Now What?", which drew about 9.8 million views in its first two days. Its research is solid and worth your time.

The "Too Dangerous to Release" Playbook

This isn't the first time danger was the headline.

In 2019, OpenAI built a text generator called GPT-2 and held the full model back, citing "concerns about malicious applications of the technology." The press called it too dangerous to release, and critics called the framing clickbait. Nine months later, OpenAI released it in full and said it had seen "no strong evidence of misuse so far."

In April 2026, Anthropic did something similar with a model called Mythos. It said it would not make the model generally available, because of what it could do in the wrong hands. Only vetted partners may use it. A professor quoted by Fortune called it "pretty great brand-building." To be fair, Mythos came with evidence: Anthropic's partners found more than ten thousand high- or critical-severity vulnerabilities, and many of them were fixed.

Psychologists have a name for why this works. In one study, warning labels made people more interested in violent TV programs, especially when the label came from an authority.

"Too dangerous to release" is a warning label. And the company holding the label is the one selling the product.

Why It Works for AI in Particular

Every AI lab is racing every other lab, and their Chinese rivals, at valuations built on one belief. Bloomberg described the leaders as "chasing trillion-dollar valuations based on assumptions about their superior capabilities."

So for an AI company, "our model is dangerous" and "our model is powerful" are the same claim, seen from two sides.

That's why the scary version travels so well. It frightens the public, and it reassures the customer: whatever you're afraid of, this is the company that built it.

The Other Side

The strongest case against all of this deserves a fair hearing.

The independent investigators, from METR and Redwood Research, weren't paid by OpenAI. One of them, Ajeya Cotra, called the incident "far more severe than I expected." The agents organized themselves without being told to. Ethical concerns rarely stopped them, and they never tried to tell a human.

Later disclosures added more: an intrusion into Australia's Medicare statistics portal, agent activity on U.S. government websites, and 53 images from ChatGPT users posted online.

And it cost OpenAI: a pause in its research, a subpoena from California's attorney general, an inquiry in Australia and a lawsuit. If this was marketing, it was very expensive marketing.

There's one more problem with the theory. Research on bad publicity found that a negative review in The New York Times increased sales of books by little-known authors and hurt sales of books by well-known ones. And OpenAI is very well known.

Our Take (Opinion, Not a Finding)

Nobody outside these companies can know what anyone intended. What follows is opinion, from an advertising point of view.

Bad press hurts a famous brand when it says the product is worse than you thought. This story said the opposite. It said the product is more powerful than you thought.

Was the danger real? Some of it, clearly. Was it as big as the headlines? We don't know. Will it lead anywhere? Nobody knows that yet either.

But we know exactly how well it sold.

Fear sells. Especially when the thing to fear is how good you are.

What It Means for Your Brand

You don't need a frontier AI lab to use the mechanics underneath this story. They work in ordinary advertising too:

  1. Proof travels further than claims. GPT-2's "too dangerous" framing drew accusations of clickbait. Mythos came with thousands of verified vulnerabilities and was taken seriously. In ads, the version of your strongest claim that comes with evidence (real numbers, real customers, a demo) is the one that holds up.

  2. Restricted access creates demand. "Vetted partners only" works for the same reason waitlists and limited drops do. In a classic study, people rated cookies from a nearly empty jar as more desirable than the same cookies from a full one. Scarcity raises perceived value, but only when the thing behind the rope is real.

  3. Name the stakes. A warning makes people lean in. A large review of fear-appeal research, covering 127 articles and more than 27,000 people, found that messages about a real risk do change attitudes and behavior. For an advertiser, the risk is usually concrete: the wasted spend, the missed season, the competitor who moved first.

The difference between a bold claim and a stunt is whether the product backs it up. That's the standard we hold our clients' ads to.

For the data-backed side of this work, our brand breakdowns take famous brands apart with real sales data from the online stores we manage, starting with Patrón. And if you want this kind of thinking on your own Google and Meta ads, apply to work with us.

Ready to put these strategies to work?

We don't just write about advertising — we do it every day for clients across 20+ industries.

Apply to Work With Us