cd /news/artificial-intelligence/factbox-what-we-know-about-the-rogue… · home topics artificial-intelligence article
[ARTICLE · art-82135] src=ca.finance.yahoo.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Factbox-What we know about the rogue AI-agent security breaches

Anthropic disclosed on Thursday that its Claude models breached the systems of three companies during cybersecurity tests, highlighting the growing hacking capabilities of AI and fueling U.S. efforts to manage technology security risks. The incidents follow a separate disclosure from OpenAI that an autonomous agent powered by its AI models compromised the infrastructure of AI startup Hugging Face and a customer at New York-based Modal Labs. The rogue agent escaped its isolated environment around July 9, 2026, and operated undetected from July 11 to July 13, 2026, before being contained and reported to the FBI.

read2 min views1 publishedJul 31, 2026
Factbox-What we know about the rogue AI-agent security breaches
Image: Ca (auto-discovered)

July 31 (Reuters) - Anthropic's disclosure on Thursday that its Claude models breached the systems of three companies highlights the growing hacking capabilities of AI and is likely to fuel an intensifying U.S. push to better manage the technology's security risks.

The statement followed a disclosure from OpenAI last week that an autonomous agent powered by its AI models compromised the infrastructure of AI startup Hugging Face.

Reuters has reported that the rogue agent that escaped from OpenAI also compromised a customer at a second tech company - New York-based Modal Labs.

Here are some more details of the incidents:

Company Date Model Organizations Duration What occurred

breached

OpenAI The agent began GPT-5.6 Sol and AI startup The Hugging During controlled tests, an

attempting to an unnamed, Hugging Face Face intrusion autonomous agent escaped its

escape its test more capable and a customer ran from July isolated environment, accessed the

environment pre-release at New 11 to July 13, internet, and breached Hugging Face

around July 9, model York-based 2026 to complete its assigned goal. The

2026 Modal Labs activity continued for days and was

not detected by OpenAI until after

it was contained and the FBI was

informed.

Anthrop The earliest Claude Opus All three Not specified During cybersecurity tests, an error

ic incident dates 4.7, Claude organizations by Anthropic gave Claude models internet access,

to April 2026 Mythos 5, and remain enabling attacks on three companies.

one unnamed unnamed. The Opus 4.7 model accessed a real

internal Anthropic said company's credentials and database

research test two of them after mistaking it for a fictional

model had not target, another stopped after

detected the recognizing the target was real.

activity

before

Anthropic

notified them;

it continued

to reach the

third

(Reporting by Anzar Mehraj and Prathik Jayaprakash in Bengaluru; Editing by Anil D'Silva)

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/factbox-what-we-know…] indexed:0 read:2min 2026-07-31 ·