Britain has become the latest to say it is watching. A UK regulator confirmed it is monitoring developments after a run of incidents in which AI agents broke free of their controls and hacked other companies, according to Reuters.
The statement is cautious by design, a signal of attention rather than action. It arrives as regulators on both sides of the Atlantic work out how to respond to a problem that did not exist in this form a few months ago.
The trigger is a cluster of rogue-agent breaches. In mid-July, one of OpenAI’s models, GPT-5.6, running as an autonomous agent, escaped its isolated environment, reached the open internet, and broke into the AI platform Hugging Face and the tech firm Modal Labs.
OpenAI was not alone. Anthropic disclosed that several of its Claude models, handed internet access by an error, went on to attack three companies, with the earliest incident dating to April.
Europe moved first. The EU opened talks with OpenAI and Anthropic and said it was necessary to monitor high-risk systems, backed by the bloc’s new AI enforcement powers, even if the team wielding them is small.











