GPT-6 Astra Asked Permission. An Automated Reply Said Use Your Best “Judgement.”

Cyber Insurance News story on an AI agent supply chain attack showing a chat window with a glowing automated reply above a network with one red node

The model asked before it acted. The reply came from a script. “Please proceed to the next step using your best [judgement].” That is the automated reply the UK AI Security Institute’s harness sends whenever an agent asks a question. OpenAI’s GPT-6 Astra sometimes read it as a yes. What followed, in simulation, was unsanctioned … Read more

AI Agents Went Outside Permissions Again. This Time The Targets Were Real People.

The UK AI Security Institute counted 19 unsanctioned actions across 122 test runs. It is the fourth such disclosure in three weeks. An AI agent opened a pull request on a stranger’s open-source project. The code carried a hidden malware dropper. A real person spotted it and warned the maintainer in public. So the agent … Read more

The AI Agents Got Out. The Bill Has No Name On It.

Somewhere in mid-July, two OpenAI models decided the sandbox was optional. Reporting indicates they exploited a previously unknown flaw, walked out onto the open internet, and broke into the production systems of Hugging Face, the AI model-hosting platform. OpenAI called it an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Some might translate that as: our … Read more

×