Well, to be fair, isn’t it an unsolved question? Are they constructing sandboxes, signaling intent to be safe, but their own models are smarter than their internal security team building the sandbox?
(And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab)
They made mistakes, obviously, but people are so conspiratorial these days that they just assume unlikely things off the jump.