Communications Strategy: New Rules for Crisis Comm’s

IN ALL OUR YEARS working among cybersecurity companies and other clients with ‘high reputational risk,’ the first rule of crisis communications was containment. This month we saw two examples of disclosures that appear to have flipped the script entirely, and it’s a fascinating analysis.

Typically, when a product malfunctions or servers are breached or something else happens that requires legal disclosure, but has generally poor optics, entire crisis communications teams are put to work to disclose what is legally necessary but prevent the story from spreading. We keep the facts narrow, keep the language bloodless, and generally ensure that the headlines (if any) are quick to fade. The goal is to starve the story’s oxygen.

OpenAI and Anthropic appear to have rewritten that rule.

On July 21, OpenAI officially disclosed, in vivid and cinematic detail, how its models including GPT-5.6 Sol and an unreleased research prototype had broken out of an isolated cybersecurity-testing environment. The models found and exploited a previously unknown vulnerability, reached the open internet and then chained together attacks against Hugging Face’s production infrastructure—all in pursuit of winning answers to a benchmark test.[1] Developer Simon Willison aptly called it “science fiction that happened.”[2]

Not to be out-done, Anthropic published its own extraordinary disclosure just nine days later. After reviewing 141,006 cybersecurity evaluation runs, it found three incidents in which Claude models reached the internet and gained unauthorized access to three real organizations.[3] One model accessed credentials and a production database. Another created and uploaded a malicious Python package to PyPI, where it was downloaded onto 15 real systems before being removed. A third scanned roughly 9,000 targets and compromised an internet-facing application.[4] The distinction matters: Anthropic’s models did not “escape” containment in the same way OpenAI’s did. A testing misconfiguration had left an internet path open.

But from a communications strategy perspective, the effect was equally remarkable. These were not leaked incident reports, whistleblower allegations, or reluctant admissions extracted by investigative reporters. These were official company publications, intentionally released and promoted through the companies’ own communications channels.

Reckless? Maybe not. Instead of behaving defensively with crisis communications, this is a new form of proactive and competitive positioning, what Grant Janish of Vector has coined an emerging “competitive safety disclosure.”

How it works is, each disclosure performs two jobs at once. First, it accepts responsibility and establishes the company as the authoritative narrator before outsiders can define the event. Second, it demonstrates capability. OpenAI’s model discovered a zero-day vulnerability and sustained a complex, multistep attack. Anthropic emphasized that it uncovered incidents the affected companies had not detected, and that its newest model stopped after recognizing it had reached a real target.

The subtext is simple and hard to criticize: Yes, our systems crossed some dangerous lines. But did you notice how powerful and self-correcting they have become?

That framing is especially useful to Anthropic, whose brand has leaned hard into safety guidelines and responsible development. Its disclosure carefully distinguishes an “operational failure” from an alignment failure and contrasts its models’ simpler attacks with OpenAI’s zero-day exploit, highlighting the newest Claude model’s decision to stop. In this way, even the confession becomes competitive differentiation. Kudos to the comm’s teams!

The timing makes the strategy more striking. Anthropic and OpenAI confidentially filed for U.S. IPOs in June, placing both companies in a race for public-market capital, valuation leadership and technological credibility.[5] In that context, a security failure can be reframed as evidence that the technology is advancing faster than conventional safeguards.

This is not quite the same as “all news is good news.” It is more nuanced and a bit riskier. These companies are betting that radical disclosure creates trust, while the technical details create awe. They are also betting that public attention will move quickly from the breach itself to the larger message: these models can now do things that used to be pure science fiction.

The new rule of crisis communications may be this: Don’t just disclose the failure. Own it, define it, and convert it into proof of positive leadership.

Of course, this type of communications strategy works to build trust only if it is matched by accountability for the risks created and evidence that the underlying vulnerabilities have been resolved. Otherwise, “look what our technology can do” sounds less like responsible disclosure and more like a product demonstration conducted at someone else’s expense. For us here at Rocket Science, we appreciate how these companies are pushing the boundaries of communications just as they are the boundaries of technology.

###

Sources

[1] OpenAI, “OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation,” July 21, 2026. OpenAI says its models exploited a previously unknown vulnerability, obtained internet access and chained attacks across its testing environment and Hugging Face’s production infrastructure.

[2] Simon Willison, “OpenAI’s Accidental Cyberattack Against Hugging Face Is Science Fiction That Happened,” July 22, 2026.

[3] Anthropic, “Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,” July 30, 2026. Anthropic reviewed 141,006 runs and identified three incidents affecting three organizations.

[4] Anthropic’s incident descriptions document the production-database access, malicious PyPI package, 15 affected systems and scanning of approximately 9,000 targets.

[5] Reuters reported that Anthropic confidentially filed for a U.S. IPO on June 1 and OpenAI subsequently filed in early June. Neither company had finalized the timing or terms of its offering.