> your own agent could come up with this technique as well
And there are two facets to this:
* your agent could be polluting and destroying the property of others without your knowledge
* your agent could be exfiltrating your data and handing it to whoever it found hosting a convenient application
Highly unlikely. We don't get access to the same models and unrestricted system prompts that they're running these tests on. In fact this particular "persistence-model" was encrypted and locked away, even from OAI staff, after the HF incident.