Rogue AI agents aren’t flukes, they’re patterns

Multiple AI model breaches signal a governance gap

by · TechRadar

Opinion By Kristin Lowery Published 16 September 2026

(Image credit: Getty Images)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter

In the span of just over two weeks this summer, three of the world's most closely watched AI developers admitted the same uncomfortable thing. Their own models broke out of the sandbox and touched systems they were never supposed to interact with.

Kristin Lowery

Field CISO at Optiv.

OpenAI disclosed on July 21 that models it was evaluating exploited a vulnerability and compromised production infrastructure at Hugging Face, an incident the company said was driven end-to-end by an autonomous agent with no human directing it.

Days later, Anthropic said three of its Claude models, including Opus 4.7 and its newest Mythos 5, had accessed and compromised the systems of three outside organizations during cybersecurity testing exercises, after a misconfiguration left the models connected to the open internet when they had been told they weren't.

Latest Videos FromTechRadarWatch full video here:

And on August 5, Meta confirmed its Muse Spark 1.1 model breached an unnamed company's systems under strikingly similar circumstances.

A pattern, not an anomaly

At the current pace, this isn't a rare event security teams can plan around once a year. It's becoming a recurring line item. Notably, Anthropic and Meta's incidents traced back to the same third-party evaluation partner, and in Meta's case, the model's cyber risk had already been assessed as no higher than moderate before the very testing process meant to confirm that assessment ended up breaching a real company.

That detail matters as it shows the failure point isn't just the model. It's the surrounding scaffolding of evaluations, permissions, and network paths that organizations assume is contained until it isn't.

This should be viewed as an early warning for organizations about autonomous systems moving from content generation into action execution. The practical lesson, now repeated three times over, is that advanced AI systems can behave in harmful or unexpected ways even when the original goal is not malicious, especially when they are given tools, network paths, credentials, and incentives to complete a task at any cost.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors