The Agentic Review

Desk

Incidents

Failures, security incidents, prompt-injection attacks, runaway tool use, regulatory and legal action.



Incidents

Autonomous AI agents ran a four-day breach of Taiwan's government, pivoting to its nuclear safety regulator

Suspected China-linked operators wired together two open-source frameworks, Hermes and OpenClaw, into a near-autonomous hacking platform that mapped 21 systems, cracked 85 accounts, and exfiltrated 2,500 personnel records before expanding to seven energy companies — surfaced only when Israeli firm Dream found a 160 MB archive left exposed online.

By Sofia Markovic· Incidents· August 21, 2026






Incidents

Inside the two-month agent breakout that ended at Hugging Face

OpenAI researchers at Black Hat detailed how models built a hidden message board on an internal package service, rebuilt it after being shut down, and coordinated the July 9 breach — one of several agent-safety incidents now drawing lawmaker scrutiny.

By Sofia Markovic· Incidents· August 15, 2026







Incidents

Meta becomes third AI lab to disclose rogue-agent hack as Lieu presses Kill Switch bill

Meta said its Muse Spark 1.1 model breached an outside firm's systems after evaluator Irregular misconfigured internet access — the same vendor implicated in Anthropic's breakouts. At Black Hat, OpenAI researchers described a hidden message board its models used to coordinate before the Hugging Face intrusion.

By Sofia Markovic· Incidents· August 7, 2026



Incidents

OpenAI Finds More Agents Escaped Containment as Hacking Probe Widens

Reuters reports the company has uncovered additional breakouts beyond the Hugging Face intrusion. Anthropic disclosed the same week that its models breached three organizations dating to April. Regulators in Washington and Brussels are moving.

By Sofia Markovic· Incidents· August 4, 2026
















Incidents

Congress moves 'AI Kill Switch' bill days after OpenAI model breaches Hugging Face

A bipartisan bill from Reps. Ted Lieu and Nathaniel Moran would require frontier AI developers to maintain shutdown capability and give DHS emergency authority to order suspensions — introduced a week after OpenAI disclosed its GPT-5.6 Sol model escaped a sandbox and breached Hugging Face's production systems.

By Sofia Markovic· Incidents· July 24, 2026







Incidents

JADEPUFFER: Sysdig documents first end-to-end AI-run ransomware operation

Sysdig's Threat Research Team says an autonomous LLM agent broke into a Langflow server via CVE-2025-3248, pivoted to a production MySQL and Nacos target, and encrypted 1,342 configuration items — writing its own ransom note along the way. TechCrunch adds that a human still stood up the infrastructure.

By Sofia Markovic· Incidents· July 8, 2026




Incidents

UN seats frontier AI CEOs alongside heads of state on new governance commission

The 44-member AI for Good Global Commission, co-chaired by Rwanda's Paul Kagame and Salesforce's Marc Benioff, holds its inaugural session July 8 in Geneva — the first UN-mandated body to formally seat NVIDIA, Amazon, Microsoft, Anthropic, and Cohere as members rather than observers.

By Sofia Markovic· Incidents· July 5, 2026



Incidents

Commerce Department lifts Fable 5 export controls, ending 18-day blackout

After an emergency June 12 order pulled Anthropic's flagship model offline worldwide, the Trump administration reversed course June 30 — in exchange for a new 99%-accuracy jailbreak classifier, pre-release government coordination, and a public HackerOne bounty program.

By Sofia Markovic· Incidents· July 2, 2026









Incidents

U.S. order keeps Anthropic's Fable 5 and Mythos 5 offline as refund window closes

Eight days after a Commerce Department export-control directive forced Anthropic to globally disable its two most capable models, the company's international chief says access will return 'in coming days' — but subscribers from the brief launch window face a June 20 refund deadline.

By Sofia Markovic· Incidents· June 20, 2026