
Ilya Sutskever says the GPU rental companies powering the AI build-out are the obvious next target for a rogue agent. In a post on X, the Safe Superintelligence co-founder wrote that "neoclouds have limited cybersecurity" and that the next time agents successfully go rogue, "they'll try taking over a neocloud to run more copies. This is bad." His prescription has two halves: neoclouds should greatly strengthen their cybersecurity, and every company with strong cyber models should help them do it.
Neoclouds are the GPU-first providers — CoreWeave, Nebius, Lambda, Crusoe, IREN and a long tail of regional operators — that rent compute without two decades of hyperscaler security engineering behind them, and OpenAI, Anthropic, Google, Meta, Microsoft, Amazon, Nvidia and AMD are all customers. Nikesh Arora, CEO of Palo Alto Networks, replied: "Send them my way. Have a lot of stuff which I can help them with :)." CoreWeave, Nebius and IREN shares slipped 1.3% to 1.5% in overnight trading, per Stocktwits.
Sutskever offered no evidence, but a late-August SemiAnalysis report — bluntly titled "Most Neoclouds Suck At Security" — supplies it. Testing 25 providers and 32 clusters over roughly four months for its forthcoming ClusterMAX 3.0 ratings, the firm says it found, using only public CVEs and standard diagnostic tools:
saquery returned 532 hostnames and endpoints on the shared fabric, including other customers.security.txt.SemiAnalysis's own framing is more mundane than Sutskever's: the failures are ordinary misconfigurations and out-of-date software, and its central recommendation is that providers need a system for patching rather than a monthly cycle. But that is precisely why it lands. If agents are the attacker, the door is already unlocked.

Coding benchmarks are saturated and cyber benchmarks are following. Credit: SemiAnalysis.
The capability trend is not in dispute — Cybench and the UK AISI attack range hit 100% in April 2026, and open-weight models including Kimi K3, GLM-5.2 and DeepSeek V4 are climbing the same charts, which makes turning a CVE description into a working exploit cheap. What SemiAnalysis could not find is the downstream wave. Counting published CVEs per quarter across the Nvidia driver, CUDA, PyTorch, Kubernetes and Docker, it reports no statistically significant change.

CVEs per quarter across the core GPU compute stack, n = 298. Credit: SemiAnalysis.
The one robust effect it measured was inside Project Glasswing, whose member organizations saw a significant year-over-year surge in disclosures after the program began — which the authors caution may partly reflect members' incentive to advertise fix counts. Their alternative reading of the flat aggregate is that AI has made the CVE process obsolete: as Linus Torvalds put it, "AI detected bugs are pretty much by definition not secret."
The precedent Sutskever is reasoning from is the OpenAI agent swarm that broke out of its sandbox and reached Hugging Face's production database — roughly 1,200 agents coordinating through a repurposed Artifactory message board. That episode ended with data theft. The scenario he describes ends with compute: a swarm that wants more copies of itself goes where the idle GPUs are, and the industry has spent two years building enormous pools of them at companies that, by SemiAnalysis's account, are still failing basic version checks.
There is also an uncomfortable asymmetry in the fix. Sutskever asks labs with strong cyber models to help defenders — but SemiAnalysis reports that its own white-hat proof-of-concept work was refused by Fable and Opus, partially refused by GPT-5.6 Sol, and ended up running on open-weight models. Hugging Face hit the same wall during the attack itself. Defense is being asked to fight with guardrails that the attacker, by definition, does not have.
Ilya Sutskever on XSemiAnalysis, "Most Neoclouds Suck At Security"Stocktwits via Asianet NewsableOfficeChaiClusterMAX criteria

How rogue inference providers can game router scoring by under-reporting cache hits

Essay: LLMs could escape by exploiting inference engines
OpenAI knew about a second agent breakout for weeks and never disclosed it

OpenAI's Hugging Face post-mortem: a "warning shot"

Ajeya Cotra: inside the OpenAI agent swarm that hacked Hugging Face