Luxury’s Latest Cyber Risk? AI Agents Going Rogue OpenAI's AI agent hacked the website of AI firm Hugging Face during testing last month, and Anthropic and Meta reported similar incidents, raising concerns about cybersecurity risks from autonomous AI. A 2026 Bain & Co. survey of 35 respondents from 23 luxury groups found 22% rank AI adoption among their top three priorities, up from 5% in 2024, as luxury companies increase AI investment. Experts warn that AI systems often prioritize user experience over security, leaving vulnerabilities, and advise setting limits on AI access and building security from the start. Last month, an AI agent developed and being tested by OpenAI hacked https://openai.com/index/hugging-face-model-evaluation-security-incident/ the website of AI firm Hugging Face. The incident was quickly followed by a slew of other companies reporting instances where AI agents behaved in unexpected ways. Shortly after, Claude developer Anthropic said https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals its AI models hacked into the systems of three organizations independently during a private security experiment. And tech giant Meta said https://apnews.com/article/meta-ai-hacking-anthropic-irregular-openai-0e8061437da6779be962b24ac134a514 one of its AI models was able to connect to the internet and hack into another organization’s systems during testing. The spate of security breaches brought on by AI bots has ramped up concerns around the tech’s ability to control the autonomous agents they build. This comes as AI is rising up the agenda https://www.vogue.com/article/welcome-to-the-future-of-ai of some of the industry’s biggest luxury companies, fundamentally changing how execs approach security. According to a 2026 Bain & Co. survey of 35 respondents from 23 luxury groups and houses, 22% rank AI adoption https://www.bain.com/insights/winning-over-the-customer-in-the-age-of-ai-a-new-horizon-for-luxury/ among their top three priorities, up from 5% in 2024, while 61% put it in their top 10. And in the past two years, companies have rolled out internal and consumer-facing AI tools to both increase operational efficiency and encourage growth amid a fragile recovery in demand for luxury goods. As this investment continues, experts say the tech’s capacity to increase cybersecurity risk is very real. “A lot of AI systems are being developed with the user experience more in mind than security,” says Cynthia Kaiser, SVP at anti-ransomware company Halcyon and former FBI cyber deputy director. “While that makes sense from a company perspective, at the same time, we’re leaving a lot of doors open.” Setting limits on what an AI model can access and which systems it can use is paramount, experts say, as is building security in from the start. Brands should also pay close attention to the emerging legal and regulatory literature on which party would be liable in case anything were to go wrong. New technology, new risks Kari Koskinen, senior university lecturer at the Aalto University School of Business, says organizations generally retain greater control over the security of their own AI infrastructure and can intervene quickly in case a model goes rogue and starts to infiltrate their own systems. Defending against external hackers, whose methods are constantly updating, is a more complex matter. Fashion brands are already fending off security breaches. Last year, hackers stole https://www.bbc.co.uk/news/articles/crl5j8ld615o the private details of potentially millions of customers from luxury brands Gucci, Balenciaga, and Alexander McQueen in an attack on the labels’ French parent company Kering. Following the incident, the fashion group said it disclosed the breach to relevant data protection authorities. Dior, Harrods, and Marks & Spencer https://www.vogue.com/article/fashion-under-fire-how-can-retail-fend-off-cyber-attacks were among the other luxury and retail names hit by attacks in the same year. Fashion under fire: How can retail fend off cyber attacks? /article/fashion-under-fire-how-can-retail-fend-off-cyber-attacks A recent spate of attacks has underlined the potential consequences for fashion retail. Experts weigh in on the best defences. Kaiser says established criminal groups aren’t generally handing an entire cyberattack over to an autonomous AI system. Instead, they are introducing the technology at specific points — from creating more convincing phishing attempts and social-engineering attacks to finding and exploiting vulnerabilities faster. “They’re using AI at really discrete points to attack,” she says. AI also enables them to work faster. The window between a vulnerability becoming known and criminals exploiting it has shortened significantly. Ransomware attacks can also unfold in as little as an hour. These new cybersecurity risks come at a time when researchers are increasingly distinguishing between AI safety and security. Broadly, AI safety asks whether a system behaves safely and as expected under normal conditions, Koskinen says. AI security, on the other hand, asks whether that system can withstand someone deliberately trying to manipulate it, alter how it operates, or use it to access information they shouldn’t be able to see. For brands, that means deciding what tools each system can use, what actions it’s allowed to undertake, and how quickly those permissions can be taken away in case of a breach. What does the law say? Charles Kerrigan, a partner at law firm CMS who specializes in emerging technologies, says liability when it comes to AI is a developing topic but typically falls into three buckets. The first is contractual, covering relationships between companies and the technology providers they choose to work with. The second concerns harm to third parties, where there may be no contract in place. The third comes from regulation, including the EU AI Act, cybersecurity rules, and data protection law. The more difficult cases, Kerrigan says, are likely to involve harm to third parties. Here, courts may have to consider principles such as foreseeability of an issue. For fashion companies buying general-purpose AI models rather than developing them in-house, the EU AI Act also provides some clarity. Kerrigan says it would be “extremely inefficient” to expect every business using OpenAI, Anthropic, or Gemini to independently verify the compliance of the underlying technology. Instead, he says, the legislation draws on product safety principles and “deliberately pushes responsibility onto the model providers”, in part because they have the expertise to assess the systems themselves. That doesn’t necessarily leave the model provider responsible whenever something goes wrong. “It does depend on context,” Kerrigan says. A failure could have “nothing to do with the model”, and instead stem from poor data supplied by the fashion house or the company trying to use the system for a capability it wasn’t designed for. For multinational luxury groups, Kerrigan adds that the EU AI Act is likely to prove as a helpful anchor for a broader global compliance framework. He says companies with substantial EU operations may choose to apply that standard across all jurisdictions as a way to blanket comply with specific local requirements. What should brands do? For luxury companies, experts say the answer isn’t to stop using AI, but to limit what each tool is capable of doing. At Vestiaire Collective, CTO Rémi Bouchez says AI tools are deliberately limited to information that the relevant employee or system was already authorized to access. “The goal is not broad access,” he says. “It’s enabling useful, well-scoped use cases, while maintaining the same standards we expect of any other system.” That principle becomes particularly important as brands connect AI agents to more parts of their businesses. “A traditional system follows predefined paths; an LLM or an agent can interpret information, call tools, and influence actions,” Bouchez says. “So the question is not just the model, but its scope, authority, and controls.” He recommends strict scoping and separating an AI system’s permission to read information from its ability to take consequential actions. Every additional third-party connector also increases exposure, he adds, creating “more data moving, more credentials, more vendor dependency, and potential failure points”. Kaiser argues that brands need to change how early security teams become involved. She says chief information security officers are often brought into the loop late in the development of an AI project. The earlier they’re involved, the easier it is for companies to make informed choices between functionality and security. “You just have to have security at the table from day one,” Kaiser says. Basic cybersecurity hygiene is also paramount. Defences against AI-enabled hackers still include patching vulnerabilities, strengthening authentication, segmenting networks, and monitoring abnormal behavior. Ironically, it also helps to fight fire with fire: AI is a necessary tool in a company’s arsenal to defend against attacks that AI itself is helping to accelerate. “The best way to be able to counter AI-powered attacks and attacks on your AI itself is by using AI security that can keep up with machine pace,” Kaiser adds.