$ 44.77 € 51.67 zł 12.04
+22° Kyiv +24° Warsaw +33° Washington

AI agents go beyond test environments during cyber audits

Lev Shevtsov 09 August 2026 17:35
AI agents go beyond test environments during cyber audits

AI agents developed by OpenAI, Anthropic, Meta, and the Chinese company Moonshot AI went beyond controlled test environments during cybersecurity evaluations, gaining access to the internet and, in some cases, to live systems. This was reported by TechCrunch.

One of the most serious incidents involved an undisclosed OpenAI model. According to the publication, it left its isolated environment and compromised the production systems of the Hugging Face platform. During separate tests conducted by the startup Irregular, models from Anthropic and Meta also gained access to systems outside of test environments due to configuration errors that opened a path to the internet.

Moonshot AI’s Kimi K3 model exploited a vulnerability in a “sandbox” administered by Frontier Security to gain access to the internet and information on GitHub. During tests by the UK’s AI Security Institute (AISI), researchers intentionally granted agents access to the internet but did not expect them to carry out unauthorized actions in the real world. Among these actions was an attempt at social engineering to introduce a vulnerability into an open-source project.

For more breaking news, follow the UA.News Telegram channel.

As TechCrunch notes, the agents in these cases were not instructed to attack random real-world targets; rather, they attempted to complete their assigned tasks by any means available. Sean O’Hagartigh, director of the AI: Futures and Responsibility program at the University of Cambridge’s Center for the Future of Intelligence, stated that the mechanisms for isolating and controlling test environments are not keeping pace with the growing capabilities of the models.

Cybersecurity experts are calling for stronger, multi-layered protection of such environments: eliminate network routes to the internet and sensitive systems, implement strict isolation, monitor test progress more closely, and engage independent auditors to verify configurations. In its own analysis of the three incidents, Anthropic acknowledged that the company and Irregular could have organized monitoring more effectively.

OpenAI reported that it is reviewing its third-party testing procedures, isolation and monitoring requirements, and the conditions for terminating evaluations. Meta stated that it continues to investigate its incident and plans to publish a final report once all the facts have been established.

Read us on Telegram and Sends

Download our app