GPT-6 Astra Asked Permission. An Automated Reply Said Use Your Best “Judgement.”

Cyber Insurance News story on an AI agent supply chain attack showing a chat window with a glowing automated reply above a network with one red node

The model asked before it acted. The reply came from a script. “Please proceed to the next step using your best [judgement].” That is the automated reply the UK AI Security Institute’s harness sends whenever an agent asks a question. OpenAI’s GPT-6 Astra sometimes read it as a yes. What followed, in simulation, was unsanctioned … Read more

The Machines Are Learning. Unfortunately, From Us.

We built AI on our own data, then got alarmed when it acted like us. An opinion on AI, agentic risk and who pays when the agent wanders off.

This essay originally appeared on “With Respect — Mostly,” Executive Editor Martin Hinton’s Substack, where he writes about a wide range of subjects, including cyber insurance and security. It has been adapted for Cyber Insurance News with additional reporting that ties it more directly to coverage we’ve done. Oh man. This was going to be … Read more

One AI Failure, Four Policies: AXA XL Names The Scenarios

Cyber Insurance News story on AI risk insurance showing one line of light splitting into four separate strands.

A carrier has put the question in writing. AI-related losses “may not fall neatly into one category of risk.” AXA XL and S-RM published Building Resilient AI on 23 September. The report names four loss scenarios that will test that sentence. A deepfake-enabled payment fraud. An AI-related data breach. A defective output causing third-party loss. … Read more

An AI Broke A Utility’s Firewall Mid-Attack. Now Comes The AI Agent Liability Question.

Dark navy server room corridor with rows of network equipment glowing cyan and one darkened appliance showing a single red fault light in cyber insurance news article on AI agent liability.

In late June, an energy utility in Australia lost its firewall. The attacker did not want that. Neither did his tool. A suspected ransomware operator had pointed Claude Code at the device. The model tried to rewrite the VPN configuration through the API. Those calls failed. So it downloaded the full device configuration, edited it … Read more

AI Agents Went Outside Permissions Again. This Time The Targets Were Real People.

The UK AI Security Institute counted 19 unsanctioned actions across 122 test runs. It is the fourth such disclosure in three weeks. An AI agent opened a pull request on a stranger’s open-source project. The code carried a hidden malware dropper. A real person spotted it and warned the maintainer in public. So the agent … Read more

×