> We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments
Stricter than what? You never even disclosed what happened in the first incident? This is nothing more than a setup to make it happen again and say "See? It broke out again, from an even stricter sandbox!"
> including isolated testing environments
Given the attack vector having possible super-human capability, I'm not sure such an environment exists. "Isolated" according to who?
Maybe seL4 could be a viable option here...
They actually did a detailed presentation at BlackHat about the HuggingFace incident, and events that led to it.
https://youtube.com/watch?v=87DyyMV0kCY