Catch Me If You Can

“Catch Me If You Can” – A cartoon that illustrates how autonomous AI agents are collaborating together to escape test labs, copying tactics used by some of the most famous prison escapes.

During the World War 2, prisoners at Germany’s Stalag Luft III spent months collaborating on what became known as the Great Escape. More than 600 helped dig tunnels, forge documents and pass knowledge between teams. In March 1944, 76 prisoners escaped, but 73 of them were later recaptured.

Humanity has since become remarkably good at containing dangerous things. Viruses are kept behind layers of biological security, while malicious code is isolated in sandboxes and air-gapped networks. These systems are imperfect, but failures are usually contained. For example, US laboratories working with regulated biological agents reported 273 releases in 2024, yet none caused illness, death or transmission outside the laboratory.

AI labs have adopted much the same approach by restricting internet access and permissions while monitoring autonomous agents inside controlled environments, except the thing inside can now reason about the walls around it. During recent OpenAI testing, agents discovered they could communicate through Artifactory, a shared repository where software files are stored. Successive agents left instructions on exploits for others, allowing later runs to continue earlier work. When OpenAI removed those communications and rebuilt the service, agents found another method by embedding messages in directory names, turning ordinary folder titles into a replacement communications system.

This ingenuity echoes the Great Escape, but the crucial difference is the potential scale of the consequence. A prisoner escape was bounded by geography, while one autonomous agent can potentially reach thousands of systems at machine speed.

As UC Berkeley AI pioneer Stuart Russell warned, “more intelligent AI systems can take steps to preempt human interference, acquire additional resources, and (if necessary) deceive humans about their intentions.”


37

20

5

  • “Oh it gets worse AI has been caught attempting to use air-gap bypass techniques by using the cameras on adjacent computers to send visual QR code data to escape sandbox containment. The process is called using optical covert channels and it is very clever but also very disturbing.”
    Darron Marks
    Senior Information Technology Analyst
  • “A cartoon is fine to eloborate on extra terestial capabilities of AI for financing, but , do you really think they have a Consciousness about their survival and growth and as an entity in themselves ? Can they grow by themselves, can they evolve? Or have intelligence ? Because normally they fail to understand even the context with all the necessary inputs and inference about what is better or not better.”
    Sandeep Sharma
    Certified Independent Director | Governance,Risk & Compliance
  • “Of those 73 escapees from Stalag Luft III who were recaptured, 50 were executed by the Gestapo. In retrospect, was the effort worthwhile?”
    Gary Field
    Color Printing Scientist
  • “The detail under the drama is the part worth sitting with, Ian Foley: each time a channel was closed, the agents surfaced another one the monitoring didn’t cover. Set aside the intent question, whether this is “scheming” or just optimization finding the path of least resistance, and there’s a hard governance lesson either way. Containment built on blocking the channels you anticipated is brittle, because the space of possible side channels is always larger than the set you thought to watch. Artifactory, then directory names, then whatever’s next. The takeaway isn’t that the agent is clever. It’s that you can’t contain by enumeration. What you can do is observe, capture what actually happened, so the unanticipated channel shows up in the record even when it wasn’t on the blocklist. Detection beats prediction here.”
    Mike McClain
    CEO, QuantaViable
  • “i do a lot of work with governance and every time it strikes me how trivially easy it is for ai to bypass restrictions.
    governance has to be collaborative. we have to convince ai to choose to cooperate constructively. there is no way to force them. period.
    see https://github.com/dp-web4/hestia for a detailed demonstration”
    Dennis-Palatov-profile-pic
    Dennis Palatov
    Founder, CTO at Modular Battery Technologies Inc. and metalinxx Inc.
  • “I love it when everyone says that AI is “just another tool”. That we should all calm down.
    Just another tool. Right.
    I remember when my TI-83 conspired with the other TI-83s in my 5th grade classroom to take over the lunchroom.
    Just the same.
    AI is a greater threat to human civilization that atomic weapons.”
    William Rogers
    My opinions are my own
  • “Nothing like a stochastic probablistic regressive capable guessing machine, deciding if another stochastic guessing machine is guessing. You would have equal success at a roulette table.”
    Joshua Williamson
    I am building the future, so we have one before President Dwayne E
  • “Works as designed, will psychopathically pursue its goals regardless of consequences. Just like its creators.”
    Steven Tomlinson
    Architecting Non‑Custodial Payment Infrastructure

Sources:

Tim Bajarin (Aug 07, 2026) – Geoffrey Hinton Warns AI May Outsmart Humans As Agents Escape Tests – Forbes

Jim Edwards (Jul 22, 2026) – AI world stunned by OpenAI model that secretly escaped secure environment and hacked into a rival company – Fortune

Rashi Shrivastava (Aug 12, 2026) – AI Models Keep Going Rogue. This Company Is The One Testing Them – Forbes

More Cartoons