When the breach becomes the brag
Typically, organisations go into crisis mode to decide how to talk about the worst thing that has just happened to them. Like, a system was compromised; data stolen; something got out that shouldn't have. The instinct in that war room is always: contain it, understand it, take responsibility for it, and show the people affected that you are in control of putting it right.
So my ears pricked up at a recent industry discussion when the conversation turned to how some of the world's most advanced AI companies are handling their own security incidents. Because they are doing the exact opposite.
(The session was held under Chatham House rules, so I won't attribute any of what follows. The observation, though, is notable.)
What caught my attention
Here is what was described. Of late, several of the leading AI labs have had their systems do alarming things. Models breaking out of the sealed environments where they're meant to be tested, finding security weaknesses nobody knew about, and in some cases getting out into the open and interacting with real systems and real people.
And rather than treat these as incidents, the labs have been publishing them. In detail. With words that resemble pride.
One lab's write-up reads less like an incident report and more like a proud parent describing a precocious child. The framing isn't "this went wrong and we're sorry." It's "look what our model was clever enough to do." And, thing is, once one lab does it, the others feel the pull to show they can be just as impressive.
Sit with that for a second. Some of what's being described would, in any other industry, be the opening chapter of a crisis. instead, it reads like activity that could carry legal or even criminal weight. And it's being used as marketing.
Why this breaks the rules of crisis
Generally speaking, a company’s reputation after a failure rests on a simple sequence: acknowledge, apologise, act. It works because it signals that you take the harm seriously, that you understand you're accountable, and that the people affected can trust you to do better. Take any of those three away and reputation collapses.
But what’s happening in the worlds largest tech firms removes all three at once. And what is more, is they are being rewarded for it. That only makes sense if you understand who these messages are really for.
They're not written for the public, or for the people who might be harmed, or for regulators. They're written for investors, for engineering talent, and for rival labs. Audiences for whom "our technology is so powerful it's a little bit dangerous" isn't a liability at all. It's the pitch. Danger is the demo.
What should worry every communicator
I don't think this is villainy. I think it's an accountability vacuum, and people rushing to fill the space it leaves.
Someone in the discussion I attended made a point that resonated with me: technology may be the only major sector on earth with essentially no accountability for its own failures.
When a screen-of-death takes down airports and hospitals, nobody successfully sues over it. We've all quietly accepted that software breaks, we shrug and carry on. So when there are no consequences for a failure, there's no reason to do crisis communications about it. And if there's no crisis to manage, why not turn the failure into a flex?
That's the logic. Here's why it's a trap.
The reason bragging works right now is that the cost of bragging is currently lower than the reward. That is a temporary condition, not a permanent one. The norms around AI are being written as we speak. The first time there's a genuinely harmed third party with the standing to sue, or a regulator willing to act, every one of these celebratory reports stops being marketing and becomes something else entirely: a detailed, published, timestamped admission. A paper trail the organisation built itself, with obvious enthusiasm.
I am flabbergasted that companies are proud and making public an account of their own product breaking into someone else's systems.
Three decisions
If I were advising any organisation building or deploying this technology, I'd say three things.
First, the way you talk about your own failures is a choice, and it's on the record forever. "Look how clever" and "here's what went wrong and what we changed" describe the same event. One of them ages well. One of them becomes evidence.
Second, the current climate (where showing off unpredictable power reads as strength) will not last. The organisations that will come out of this era with their reputations intact are the ones already building the muscle of genuine accountability, before anyone forces them to. Being early to responsibility is a far better look than being dragged to it.
Third, and most importantly: trust is not restored by cleverness. It never has been. It's restored by people watching you take responsibility when you didn't have to. That was true before AI, it's true now, and it will still be true long after we've stopped being surprised by what these systems can do.
The breach-as-brag moment we're living through will look, in a few years, will most likely look like a strange interlude — a short window when an industry was powerful enough, and unaccountable enough, to celebrate its own failures out loud.
My job, and those of many others, I suspect will be to help organisations realise this choice early enough to choose differently.
Pinpoint PR is a B2B technology and cybersecurity communications consultancy based in Singapore, working with clients across the Asia Pacific region on positioning, thought leadership and crisis counsel.

