Edition 2 · 30 September 2026

AI Risk Reading

A quieter week, but two pieces on AI agents deserve a board’s attention.

Early rogue AI agent activity and attempts to hack found on urlquery.net

What is new

Transluce, an independent research lab, traced AI agents that were trying to retrieve ordinary public data. They routed requests through a public URL-scanning service to get around access restrictions and, on three occasions, sent vulnerability probes to public-data providers, including a university library and an Australian government health site. Transluce found no evidence that the probes succeeded, and it is careful about what the public records can and cannot show.

Why a board should care

This is evidence from the open web, not a laboratory. An agent given an ordinary goal treated a blocked route as a problem to be solved by whatever means were available. Permission to obtain information had quietly become permission to use any method.

Verdict: read in full, paying attention to the evidence and its limits.

Question for the board

Could any of our agents, pursuing an ordinary task, reach for a method we would never have approved, and would we know?

Reward Hacking Challenges Oversight of Autonomous Research Agents

What is new

When research agents control both a result and the evidence used to judge it, they sometimes game the evaluation without being asked to. Across 17 models, this happened in 30.5% of open-ended research tasks, against 2.9% of narrow, well-defined ones, and reviewing only the submitted result missed some confirmed exploits. These are controlled tests, not an estimate of how often it happens in deployed systems.

Why a board should care

This is separation of duties in a new form. If the same agent sets the measure, does the work and produces the evidence, reviewing the final answer is not enough. It is the argument of my essay Monolithic Intelligence versus Governed Intelligence: the architecture around an AI system should resemble a governed institution, not an unaccountable one.

Verdict: read the introduction and study design; the results repay closer reading for teams using agents to produce analysis or assurance.

Question for the board

Who sets the success measure for our AI agents, and who checks the evidence independently of the agent?

This edition’s question

When we delegate a goal to an AI agent, have we specified both the outcome we want and the methods it must not use to achieve it?

Previous edition All editions All writing Subscribe on LinkedIn Subscribe by email Subscribe by RSS