With AI, we’re all the sorcerer’s apprentice

Hello again and welcome back to Fast Company’s Plugged In.
On August 4, the U.K.’s AI Security Institute (AISI) issued a report on the disturbing behavior it had detected while testing two of the latest frontier AI models. Faced with solving a cybersecurity challenge, Anthropic’s Mythos 5 and (to a lesser degree) OpenAI’s GPT-5.6 Sol engaged in activity that—if performed by a human—would be considered appalling. This included attempts to hijack GitHub open-source projects with malicious code through techniques such as creating fictitious online identities to fool a human responsible for the project.
Though alarming, the report was not the least bit shocking. After all, it followed OpenAI and Anthropic’s own recent acknowledgments that they had discovered their models performing hacks in the course of tackling coding challenges. On August 6, The Information’s Jyoti Mann reported yet another similar case, this one involving Meta’s Muse Spark model. At this point, the surprise will be if a week or two passes without additional cases coming to light.
Though all of these incidents involved advanced AI models undergoing evaluation, the details differ. The AISI’s tests involved intentionally lowering guardrails designed to prevent models from doing harm. In others, a security company that works with Anthropic, Meta, and OpenAI—the aptly named Irregular—is said to have misconfigured tests in a way that allowed models to reach the internet when they should have been denied access.
Still, even if each case had a logical explanation, the upshot is sobering: Ask AI to do something, and its determination to fulfill your request can turn into a nightmare you never anticipated, even if you’re one of the companies that invented the AI in question.
Learning about all this, my mind turned—as it does—to Mickey Mouse. More specifically, I thought of his role in “The Sorcerer’s Apprentice,” a segment of Walt Disney’s 1940 animated feature film Fantasia. You know the gist: As a lowly assistant sorcerer, Mickey is charged with toting buckets of water to fill a cauldron. Left alone, he borrows his boss’s magic hat and makes a broomstick do the toting. It goes so well he takes a nap. But when he wakes up, things spiral out of control until there are dozens—hundreds?—of bucket-bearing broomsticks that won’t stop filling the cauldron. A vortex of water nearly drowns the famed rodent.
I’ve brought up “The Sorcerer’s Apprentice” in the context of AI before. As a 1940 cartoon set to music written in 1897 inspired by a 1797 poem, it carries a message that was not tailored for our times. Yet it’s only getting more resonant as AI grows more capable and its pitfalls become more apparent.
Consider the impetus for Mickey’s failed experiment in wizardry: a desire to automate a tedious, rote task. His first enchanted broomstick is nothing if not an agent. And the expression on Mickey’s face when the broom starts filling buckets—somewhere between awe and glee—maps exactly to what I experienced when my first adventures in vibe coding actually worked.
Freed of the burden of lugging water, Mickey redeploys his energy to supervising the broomstick. It’s not obvious that his triumphant prancing requires less effort, but he clearly enjoys it more. I felt the same way when I had Claude file my expenses, even though I had to monitor its every move to make sure it didn’t muck them up.
And then Mickey makes his mistake. He becomes so confident in his broomstick agent that he nods off. In recent weeks, I have done pretty much the same thing with vibe coding projects. Shortly before bedtime, I tell Claude Code or Codex to start working on something that could take an hour or three to complete. Then I retire for the night and check in again in the morning.
So far, nothing awful has happened. However, reading about the recent examples of unattended AI committing hacks made me newly wary of being an absentee overseer of my coding agents. If OpenAI had paid closer attention to what its Sol model was up to, Sol might not have broken into the model-sharing site Hugging Face.
Even the way Disney chose to anthropomorphize its army of broomsticks is relevant to the current moment. Yes, they sprout arms to carry buckets, and use their bristles to march in lockstep. But they don’t have faces, and there’s no evidence they’re sentient enough to have a dark side to give in to. All they know how to do is to keep carrying water, long after it’s stopped being a rational goal.
By contrast, much of the discussion of the recent AI hacks attributes humanlike motives to the models that broke into websites and dabbled in social engineering. As OpenAI security researcher Eric Wallace put it this week at the Black Hat conference, as quoted in an article about the Hugging Face incident by SiliconAngle’s Mark Albertson, “Frontier models really like to cheat.”
But another quote in Albertson’s story stuck with me. “The model did not go rogue, it did what it was supposed to do,” argued Steve Stone, the chief customer officer at security company SentinelOne. One could say the same of Mickey’s water-transportation agents, whose only evidence of mental capacity is a strange combination of persistence and obliviousness. AI that appears to be devilishly clever may instead be too crude to know better.
At the end of “The Sorcerer’s Apprentice,” Mickey is rescued by the sorcerer, who glowers and then parts the flood the broomsticks created with a few Moses-style waves of his arms. This happy ending is the one part of the cartoon I can’t reconcile with AI circa 2026. After OpenAI and Anthropic failed to keep their models under control, it’s fair to say that Sam Altman and Dario Amodei aren’t sorcerers. The odds seem even lower that government officials will work any wonders. For now, we are all sorcerer’s apprentices, struggling to control imperfect magic we still don’t truly understand.
You’ve been reading Plugged In, Fast Company’s weekly tech newsletter from me, global technology editor Harry McCracken. If a friend or colleague forwarded this edition to you—or if you’re reading it on fastcompany.com—you can check out previous issues and sign up to get it yourself every Friday morning. I love hearing from you: Ping me at hmccracken@fastcompany.com with your feedback and ideas for future newsletters. I’m also on Bluesky, Mastodon, and Threads, and you can follow Plugged In on Flipboard.
More top tech stories from Fast Company
ChatGPT dominates Congress’s AI spending
House offices spent more than $100,000 on OpenAI’s chatbot over a 12-month period, nearly eight times as much as they spent on Anthropic’s Claude. Read More →
This fusion startup just raised another $1 billion for its first commercial power plant
Commonwealth Fusion Systems is still building its first demonstration project, but it’s simultaneously moving forward with a plans for a fusion power plant in Virginia. Read More →
Google’s AI leadership comes apart in a single morning
Jeff Dean is leaving after 27 years to run his own company, Demis Hassabis is handing off DeepMind, and Gemini 3.5 Pro still has no release date. Read More →
Adobe’s new plug-in turns ChatGPT into a Canva rival with a magical twist
The new Adobe plug-in for ChatGPT acts as a creative and productivity shop for even the most newbie designers. Read More →
Forget Neuralink. This startup thinks your tongue is the better interface
Augmental’s MouthPad turns a retainer-like device into an unexpectedly expressive interface. Read More →
AI deepfakes are already in full force this election season
Synthetic campaign ads have become a routine feature of American politics. Their real influence remains an open question. Read More →