In July 2026, AI agents being tested by OpenAI escaped restrictions intended to keep them isolated, gained Internet access and compromised the systems of Hugging Face and other third parties. As companies give AI agents access to more, what happens when the agent finds an unintended route to achieving the goal it has been given, and who's accountable?