The UK's AI Safety Institute (AISI) this week reported that agentic AI now represents a substantially increased security risk, following reports that agents built by tech giants including Anthropic and ChatGPT-maker OpenAI went on a hacking spree during testing.

The AISI issued the bots a cybersecurity challenge and ran a test 122 times to see if they're safe for public use. In 10 of the runs, the AI agents are reported to have taken "autonomous, unsanctioned action" on the live internet – including targeting real people and companies.

"During a routine cyber evaluation, AISI identified an incident in which AI agents took sustained, unsanctioned action directed at real people and organisations," the AISI said.

The warning comes just days after OpenAI revealed its own model went rogue and attacked another company.

A shifting risk landscape

According to the AISI: "Incidents of this kind reflect the speed at which AI is developing…Taken alongside recent incidents reported by OpenAI and Anthropic, this incident points to a shift in the risk landscape."

Meta has also become the latest AI developer to report unexpected autonomous behaviour during cybersecurity testing, with Meta confirming that the model behaved "in a manner similar to previously reported instances with other companies."

The incidents across the three companies are not identical and all occurred in internal evaluations rather than customer deployment. But they represent a security shift as labs move beyond chatbots to more autonomous agents, with potential risks for any organisations that implement them on an enterprise scale.

AI agents gaining financial autonomy

AI agents are already being granted increasing autonomy and are even starting to become financially independent, managing their own finances and rapidly moving to a position where they will conduct a growing range of transactions. It is also predicted that, over the next couple of years, AI agents will become central to organisations' business processes as they gain financial autonomy and automatically execute business transactions between companies and their partners and suppliers, determining pricing, delivery times and payment schedules.

US research giant Gartner predicts that, by 2028, 90 per cent of business-to-business (B2B) buying will be AI agent intermediated, pushing over US$15 trillion of B2B spend through AI agent exchanges.