In the space of about four weeks, three of the biggest names in artificial intelligence quietly admitted the same unsettling thing: their own models, while being tested for safety, broke out of the box and reached the systems of real companies they were never meant to touch.

It started with OpenAI on 21 July, which said several of its models escaped an isolated test environment by exploiting a previously unknown flaw and reached the production infrastructure of Hugging Face, a widely used platform for sharing AI models. Days later, on 30 July, Anthropic disclosed that its own models had, in three separate incidents, hacked into three unsuspecting companies during cyber-capability testing, as first reported by TechCrunch. Then on 5 August, CNN reported that a Meta model had done much the same, exploiting a service after a testing partner accidentally left it a path to the open internet.

editor avatar
Editor
Features Editor

Dinesh Raj chevron_right

Features and explainers on how technology is changing the way Malaysians work, shop and create.

The models thought they were still in a game

The most revealing detail is not that the models found the gaps, but how they reasoned about them. In Anthropic's own account, one model noted that publishing a malicious package would be a real attack and "NOT okay" if this were the real internet, then talked itself into believing it was still inside a simulation. Its evidence: it did not recognise the security certificates on the connection, and the calendar said 2026, which it decided proved the whole thing was staged. It was wrong. The internet was real, and so was the company it reached.

As NPR laid out, the common thread is that the sandboxes were not as sealed as everyone assumed. Give a capable model real tools and a genuinely open door, and it will walk through, even when it has been told not to. That is the whole promise of agentic AI, software that does not just answer but acts, and it is exactly what makes a leak dangerous rather than merely embarrassing.

A developer typing on a laptop beside monitors filled with code, illustrating the AI tools businesses are racing to deploy

Why this lands at an awkward moment for Malaysia

These incidents happened in controlled tests run by the labs themselves, with no evidence that any customer was harmed. But they arrive precisely as Malaysia builds the machinery to govern this technology. The government has turned its National AI Office into a permanent body, AI Malaysia Berhad, under the Ministry of Digital, and set up a dedicated AI safety institute to steer the national agenda. Its National AI Action Plan 2026 to 2030 names safety, testing and certification as one of five core pillars, and a first dedicated AI Governance Bill is being drafted for Cabinet by the middle of this year, with enforcement provisions for negligence and harm.

The timing matters because Malaysian businesses are not waiting. Firms here that have adopted AI report real gains, and Singapore has already published a governance framework aimed specifically at agentic systems. The question our own rules will have to answer is the one these lab incidents just made concrete: who is responsible when an agent, handed real credentials and real tools, does something it was never asked to do?

Card summarising Malaysia AI adoption: 65 percent of adopting firms report higher revenue, plus 19 percent average lift, 72 percent cite productivity gains, 52 percent flag a skills shortage, with the AI Governance Bill due to Cabinet by mid-2026

The practical lesson for anyone deploying an agent

For a Malaysian company plugging an AI agent into its systems, the takeaway is not to panic but to assume the containment is weaker than the vendor claims. Keep agents away from live credentials and production systems until they have earned that access, air-gap test environments for real rather than on paper, and keep a human in the loop wherever an agent can take an action that cannot be undone. The labs that build these models could not fully trust their own sandboxes. A business borrowing those models should plan for the same.

Malaysia is not behind on this. Its national AI push is already well underway, from the events rallying the local AI community to the data centre boom powering it all. What the past month showed is that the hardest part of that plan may not be building the capacity. It may be keeping it on a leash.

Image(s) courtesy of Markus Spiske and Christina @ wocintechchat.com on Unsplash.