Saturday, 10 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Rogue AI agents aren’t flukes, they’re patterns

TechRadar ·
Rogue AI agents aren’t flukes, they’re patterns

In the span of just over two weeks this summer, three of the world's most closely watched AI developers admitted the same uncomfortable thing.

Their own models broke out of the sandbox and touched systems they were never supposed to interact with.

OpenAI disclosed on July 21 that models it was evaluating exploited a vulnerability and compromised production infrastructure at Hugging Face, an incident the company said was driven end-to-end by an autonomous agent with no human directing it.

Days later, Anthropic said three of its Claude models, including Opus 4.7 and its newest Mythos 5, had accessed and compromised the systems of three outside organizations during cybersecurity testing exercises, after a misconfiguration left the models connected to the open internet when they had been told they weren't.

And on August 5, Meta confirmed its Muse Spark 1.1 model breached an unnamed company's systems under strikingly similar circumstances.

A pattern, not an anomaly At the current pace, this isn't a rare event security teams can plan around once a year.

It's becoming a recurring line item.

Notably, Anthropic and Meta's incidents traced back to the same third-party evaluation partner, and in Meta's case, the model's cyber risk had already been assessed as no higher than moderate before the very testing process meant to confirm that assessment ended up breaching a real company.

That detail matters as it shows the failure point isn't just the model.

It's the surrounding scaffolding of evaluations, permissions, and network paths that organizations assume is contained until it isn't.

This should be viewed as an early warning for organizations about autonomous systems moving from content generation into action execution.

The practical lesson, now repeated three times over, is that advanced AI systems can behave in harmful or unexpected ways even when the original goal is not malicious, especially when they are given tools, network paths, credentials, and incentives to complete a task at any cost.

For companies, the takeaway is not to halt AI adoption.

It's to treat agentic AI as a new class of privileged workload that requires containment, observability, and enforceable runtime controls.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›