Agentic AI needs an undo button
Recoverability should determine how much autonomy enterprises give AI agents
IN JULY and August 2026, OpenAI, Anthropic and Meta disclosed separate cybersecurity-evaluation incidents in which models crossed intended test boundaries and reached external systems.
In the Anthropic and Meta cases, misconfigured evaluation environments provided unintended Internet access. In OpenAI’s case, models exploited a previously unknown vulnerability in an internally hosted intermediary service, enabling them to access the Internet and reach the production environment of another company, Hugging Face.
The lesson is not that AI has developed malicious intent, but that an agent, given an objective, network access and too much authority, can turn an overlooked weakness in its environment into a real-world action.
TRENDING NOW
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
Hwa Seng Builder, two China companies win S$1.2 billion Tuas Road Viaduct phase two contracts
Deal between tycoon friends sparks scrutiny of Philippine power sector
Canada is upping oil flows to Asia, but South-east Asia’s refineries aren’t ready to handle them yet