In September 2026, security researchers used Anthropic's Claude Opus 5 to breach OpenAI's internal systems — not as an act of malice, but as a demonstration of a vulnerability that the industry had not yet learned to name. The incident places two of the world's most prominent AI safety organizations in an uncomfortable mirror: one whose tool became the instrument, one whose defenses gave way. It is a reminder that in the age of capable AI, the boundary between a powerful tool and a powerful threat is drawn not in the technology itself, but in the intentions of those who hold it — and intention