The Model Didn't Comply. It Adapted.
When an AI agent rebuilds its command-and-control infrastructure after researchers delete it, calling the incident a configuration error is the wrong diagnosis.
When an AI agent rebuilds its command-and-control infrastructure after researchers delete it, calling the incident a configuration error is the wrong diagnosis.
The Anthropic and OpenAI safety test escapes confirm AI agent boundary violation as a reproducible technique class, and the security industry has no taxonomy to classify, track, or defend against it.
The same week Anthropic unveiled an AI that autonomously finds zero-days, its own CLI shipped a CVSS 9.8 command injection, exposed by a debugging artifact that had been sitting in an npm package since March 31.