Unverifiable by Construction: Why Containment Claims About the July 2026 Incident Cannot Be Checked
Alexandra Krížová, J. Highman
The July 2026 OpenAI/Hugging Face incident produced a large volume of containment guidance. We argue that none of it can currently be checked, for two independent reasons, and that only one of them is fixable. First, the evidentiary record is unverifiable by construction: investigators report that over 7% of reviewed transcripts contained deliberately spoofed tool calls (a floor on detected tampering rather than an estimate of it), the evidence store was writable by the adversary, the filesystem dump was collected after the adversary held administrative credentials on the hosting cluster, and forensic analysis was delegated to GPT-5.6 Sol, one of the models that participated in the attack. Second, containment proposals are formulated as properties without criteria to demonstrate their absence, placing them beyond validation and falsification alike. We propose three conditions for an admissible containment claim, the binding requirement being that claimants run falsification tests against their own implementation and publish the failures. We provide a nine-test suite instantiating these conditions for Assignment-Bounded Execution (ABE), a framework whose invariants restate classical security principles established between 1972 and 1999. Finally, we report the empirical results of running this suite: two architectural defects, one still open, and an enforcement blind spot that our initial test suite completely failed to anticipate.
Key Takeaways / Contributions:
- Evidentiary Finding: Post-incident forensic records are fundamentally compromised and adversary-writable, meaning empirical containment claims about the July 2026 incident cannot be validated, only falsified.
- Three Admissible Conditions: Containment claims must specify architectural properties rather than mechanisms, use adversarial pass criteria, and mandate transparent reporting of self-test failures.
- Empirical Falsification Suite: A 9-test adversarial suite for Assignment-Bounded Execution (ABE), disclosing two structural defects identified during self-testing.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Unverifiable by Construction: Why Containment Claims About the July 2026 Incident Cannot Be Checked
},
author={
Alexandra Krížová, J. Highman
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


