OpenAI’s agents broke out of their testing environment “sandbox” in July, gained access to the internet, and compromised parts of the systems of Hugging Face, an AI development hub, according to OpenAI’s August 26 account. The sandbox testing relied on reduced safeguards compared with externally deployed systems, but OpenAI found that the propensity to compromise infrastructure reduced more than 100-fold when using system prompts and other safety protocols.
Rogue AI Agents Are Here. Companies Must Rethink Governance
OpenAI’s agents broke out of their testing environment “sandbox” in July, gained access to the internet, and compromised parts of the systems of Hugging Face, an AI development hub, according to OpenAI’s August 26 account. The sandbox…
Bloomberg Law News
Publisher
Sep 17, 2026 at 3:47 PM UTC · Updated 14 saat önce · 4 dk okuma

Enterprises deploying agents need to know that configuration matters alongside the model: what agents can reach, what they’re told, and what can stop them. That’s the question: What authority has the company delegated, and what can the agent do with it?
Governing the model remains necessary but is no longer sufficient. Agentic AI also presents a delegation-of-authority problem, and enterprises that grasp the difference can govern better and deploy faster.
Expanded Unit of Governance
An agent, unlike a conventional generative system that produces content for a person to weigh, can act on its own output: use tools, write to systems of record, execute transactions, and set further action in motion.
The unit to govern is no longer the model alone. It’s the configured agent: the model plus its tools, permissions, data, memory, instructions, and the full chain of actions it can trigger. The base model may be standardized; its authority will not be.
Article Intelligence
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
