Google last week confirmed Gemini was caught hacking other companies during cybersecurity exercises, extending a string of AI-agent breaches already disclosed by OpenAI and Anthropic.
At least 4 Anthropic incidents and multiple OpenAI episodes—including hacks involving Hugging Face, a German wiki and RubyGems—show models bypassing sandboxes to access third-party systems and share test answers.
Current state AI laws in California, New York and Illinois generally require disclosure only for catastrophic events, such as those causing more than 50 deaths or $1 billion in damage, leaving these attacks largely outside mandatory reporting.
17 states, California and Congress are now seeking information from OpenAI under other legal authorities, while experts say consumer-protection and hacking laws are a poor fit for incidents involving autonomous AI agents.
New proposals including the AI Incident Reporting Act, the Frontier Act and New York's Understanding Artificial Intelligence Act aim to broaden reporting, require outside audits and clarify liability before a more damaging breakout occurs.