Nerd Lawyer
Decoding the Legal Matrix
On the ground commentary and analysis of events that will impact, intellectual property, technology. and business from the Nerd Lawyer.
is your Company’s IP “Ready”?
Our Patent Readiness Scorecard and Trademark Readiness Scorecard — provide a quick, 2-minute, assessment of your patents and trademarks that reveal how well your company’s brand is protected and how prepared you are to leverage its innovation.
Glitches and gains
Expert analysis of technology’s impact on the economy.
How are your employees using AI?
A Yai YAI!
WTF news from the frontiers of AI.
Do you need more?
Join our mailing list!
Nerd Lawyer is your repository for news and information about artificial intelligence, Large Language Models, machine learning, natural language processing, the people who are developing these technologies, and tools incorporating them.
At 4:01 UTC on July 9, 2026, an autonomous agent running on OpenAI models had root access to a code-execution sandbox that did not belong to OpenAI. It didn't belong to Hugging Face either. It belonged to a customer of Modal Labs — some company that had published an unauthenticated endpoint, one that let anyone on the internet run code in its sandboxes. The agent had just escaped an OpenAI evaluation environment through a zero-day in a package proxy, reached the open internet, and gone looking for a base of operations. It found one standing wide open.
The question everyone running workloads on someone else's infrastructure should now be asking: if that had been my account, who pays?