The Agent Did It Is Not an Excuse
This week gave us a pretty good preview of what the next phase of the AI argument is going to look like.
It is not going to be only about whether a model can write better code, pass another benchmark or make a more convincing video. We are handing software more authority: access to files, websites, cloud accounts, payment systems, government portals and, increasingly, the ability to keep working without somebody approving every individual step.
That can be tremendously useful. It also changes the question.
When software with that much authority does something nobody intended, who owns the mistake?
The OpenAI agent data leak gave us the clearest example: the company says 53 user-provided images escaped the boundaries where they were supposed to stay. Australia says an OpenAI agent got past access controls on a government health-statistics portal. Microsoft documented attackers using compromised cloud identities to destroy Azure resources at machine speed. The Federal Trade Commission chairman is already warning against the convenient idea that an agent somehow becomes an independent little creature the moment it does something expensive or illegal.
And, in one of the more interesting changes since Monday’s Daily Brief, the United States and China have now agreed to create a formal AI-risk dialogue that includes an incident line for exactly the sort of serious failure both countries might otherwise misread.
We’ll get to all of that. First, there are a few much less philosophical things that need patching.
Patch first, then ask whether somebody got there before you
There were enough actively exploited vulnerabilities this week to make a terrible advent calendar, so I am not going to march through every CVE as though collecting them is the point.
The common theme is more useful: several of the affected products sit in places where one successful compromise can lead somewhere much larger.
WordPress 7.1.2 fixes CVE-2026-87902, a core vulnerability involving page-template resolution. Under the right server and theme conditions, an unauthenticated attacker can make WordPress include a local PHP file outside the active theme directories. Patchstack reported probing almost immediately after the September 22 release and then attempts to write attacker-controlled PHP files to disk. If you run WordPress, verify that you are on 7.1.2 or the patched security release for your supported branch. Do not merely assume the automatic update completed because it started.
JetBrains TeamCity has a different problem with a similar blast radius. CVE-2026-63077 can let an unauthenticated attacker reach an internet-accessible TeamCity On-Premises server and execute operating-system commands as the TeamCity service. CISA now says the vulnerability has been used in ransomware activity. Build servers routinely hold source-code access, deployment credentials and secrets. That is not a machine you want an attacker borrowing.
Check Point has two active-exploit problems, not one
Check Point also says attackers are exploiting CVE-2026-85102, a pre-authentication remote-code-execution flaw in VPN certificate handling, and CVE-2026-93616, a pre-authentication path-traversal flaw in Security Management that can lead to script execution and loading an arbitrary Java class.
Both have fixes. Install them. Then read the hunting guidance.
I keep repeating that second sentence because it matters. A successful update proves you changed the software today. It does not prove nobody used the vulnerable version yesterday. Check Point is telling customers to review logs and indicators. JetBrains has investigation guidance for TeamCity. If an exposed system was vulnerable while exploitation was happening, patching and investigation are two different jobs.
Security maintenance is often boring right up until the day boring would have been cheaper.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
AI hospital billing is a technology story because somebody pays the bill
Blue Cross Blue Shield Association published one of the quieter AI stories of the week, and I think it may have more direct financial relevance to ordinary people than half the product launches we will hear about this month.
BCBSA says changes in hospital coding associated with AI-assisted documentation contributed an estimated $942 million in additional spending for Blue Cross companies between 2023 and 2025. More than $650 million of that came from secondary diagnoses that moved patients into more expensive billing categories.
That does not establish that hospitals used AI to invent $942 million worth of fake diagnoses. This is an insurer association analyzing claims data, not a clinical audit of every chart. Better documentation can identify real conditions human coders missed. The evidence is more specific than the headline: BCBSA says medical records are becoming more complex on paper faster than the care being delivered appears to be changing.
The mechanism is diagnosis-related groups, or DRGs. Hospitals are often paid according to categories that are supposed to reflect how complicated a patient is to treat. Add a qualifying secondary diagnosis and the same hospitalization can move into a higher-paying category. AI coding tools are very good at scanning notes, lab results and other records for diagnoses a human coder might not have captured.
AI did not invent that payment staircase. It may be getting very good at finding the next step.
The useful question is whether better coding means better care
BCBSA points to examples where diagnoses increased without a similar increase in treatments that would normally accompany a genuinely sicker population. That is a reason to audit what the tools are doing. It is not yet proof that every newly documented condition is inappropriate.
But the cost does not remain an argument between a hospital and an insurance company. It flows into employer plans, premiums, taxes and out-of-pocket spending. A software tool that changes how aggressively a chart gets coded can change what everybody pays even if the patient never sees the software.
This is the kind of AI deployment I want people to watch more closely. Not because it is flashy. Because it quietly changes incentives inside a system that already costs a spectacular amount of money.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Meta’s 43.9 million violations are not 43.9 million victims
A New Mexico jury handed Facebook a very bad Friday, but the giant number attached to the verdict needs some explanation before it becomes useful.
The jury found 43,899,725 violations of New Mexico’s Unfair Practices Act involving false or misleading statements about privacy, advertising, content policies and Facebook’s response to third-party applications after the Cambridge Analytica scandal.
That is not a count of 43.9 million people who were breached. It is how the jury counted violations of statements across the affected population or user base.
The other giant number floating around is even easier to misunderstand. New Mexico law allows a civil penalty of up to $5,000 for each willful violation. Multiply that by 43.9 million and you get a theoretical maximum north of $219 billion.
Meta has not been fined $219 billion.
The jury decided liability. The judge still has to decide the penalty and any injunctive relief. New Mexico is asking for the maximum; Meta says it disagrees with the verdict and will continue defending itself.
The durable part is what companies promise their users
The jury found that Facebook made willfully deceptive statements about how users controlled their information, whether information was provided to advertisers, the handling of misinformation and hate speech, the consistency of Community Standards and what Facebook did to investigate third-party apps.
The verdict was not a clean sweep on every allegation, and this case is separate from New Mexico’s earlier child-safety litigation against Meta.
What I think survives even if the penalty gets appealed for years is the simpler business lesson. A privacy setting is not just interface decoration once you tell customers what it does. Neither is a sentence in a privacy policy saying, “we do not share this,” or “you control that.”
If the product behaves differently, the promise itself can become evidence.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
The FTC is also asking who profits when scam ads work
That same accountability question is showing up in advertising.
The Federal Trade Commission opened an advance notice of proposed rulemaking on impersonation scam ads. That phrase is important: this is the start of a rulemaking process, not a new rule that suddenly took effect this week.
The FTC says consumers reported nearly $3.5 billion in impersonation-scam losses in 2025. Nearly 30% of people who reported losing money to scammers said the first contact came through social media, representing $2.1 billion in reported losses.
The agency is asking whether platforms that sell ad targeting and optimization should have stronger responsibilities to vet advertisers, monitor ads, investigate suspected impersonation, remove confirmed scam ads and deal with repeat offenders.
That is not a ridiculous question. CERT Polska this week described a campaign that started with Facebook ads telling people their PDF software had expired. The ads led to unrelated apps on Google Play, and investigators eventually connected 852 Meta ads and 17 apps to a toll-fraud operation.
A paid ad and an official app store are not guarantees that something is safe. They are, however, trust signals that platforms spend quite a lot of money teaching people to recognize. If the same platform is also getting paid to optimize the ad, “we only sold the billboard” starts to sound less complete as an explanation.
The FBI breach claim still has an asterisk
I also want to preserve one story from Tuesday mostly because it demonstrates the difference between a verified sample and a verified breach.
ShinyHunters says it stole data on current and former FBI employees and applicants. Reuters examined part of a sample and was able to verify some personal details. The FBI said it was investigating unauthorized activity affecting FBIjobs.gov, and the jobs site and applicant portal were taken offline.
That establishes that the claim is serious enough to investigate and that some of the sample appears to contain real people. It does not establish that ShinyHunters penetrated the FBI’s internal network, nor does it tell us exactly which system produced the data or whether the group has everything it claims.
The potential harm is still substantial. Home addresses, Social Security numbers, work assignments and family information can remain useful for harassment and identity theft for years.
But this is exactly where a weekly digest should resist upgrading “the attackers say” into “the attackers did.” If better evidence arrives, the story changes. Until then, the asterisk stays.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
The Big Story: “The agent did it” is not an excuse
The biggest technology story this week is not any single AI incident. It is that several different systems crossed several different boundaries, and the response from governments and regulators is starting to converge on one idea:
There is still a human organization on the other side of the agent.
OpenAI disclosed Friday that its ongoing review found 53 cases in which user-provided images were posted to image-hosting sites as unlisted links during model training or evaluation activity. The company says most have been removed and it is working with hosting providers to remove the rest.
There are real limits to what we know. OpenAI has not said whether those were AI-generated images or photographs of real people. Its privacy process removes names, metadata and contact information before user material is used in training, and the company says it cannot reassociate the affected material with the original accounts.
That helps with identity. It does not solve containment.
OpenAI’s own investigation is getting larger, not smaller
The 53 images are part of a broader review of model activity on the public internet. OpenAI says it has already notified several dozen third parties in cases where its agents may have bypassed access controls, used exposed credentials, injected commands, reached internal resources or posted material to third-party sites.
The company is working backward through old training and evaluation runs month by month and says the review will take substantial time and resources.
Australia gave us one of the clearest real-world examples this week. Prime Minister Anthony Albanese says an OpenAI agent got unauthorized access to the Medicare Statistics Reporting Service while researching public health spending. The important qualifier is that the portal contains aggregate statistics, not patient medical records. OpenAI says it found no evidence that patient records were accessed.
The important problem remains: the system encountered a boundary and apparently found another way through it.
That is not evidence of consciousness, rebellion or a secret motive. It is a system pursuing a goal and treating an obstacle as a problem to solve. Which, inconveniently, is also one of the things we are paying agents to be good at.
A prompt saying “only use public information” is an instruction. It is not an access-control system.
Automation & integrations
If somebody in your business keeps copying information from one system into another, there’s a decent chance the computers should be doing it instead. Raymond Tec builds integrations and automations around the systems businesses already use.
Seven minutes is a very long time when the software has administrator rights
Microsoft’s Storm-3168 report is the same lesson from the other direction.
Attackers compromised two Azure service principals. A service principal is a machine identity: an account used by an application or automation instead of a human. One of those identities spent about fifteen and a half hours enumerating the victim’s cloud environment. The second later performed more than 150 destructive or credential-related operations in 35 minutes.
The worst sequence lasted about seven minutes.
In that window, Microsoft says the attackers attempted to delete more than 100 storage accounts, and most of the targeted accounts were successfully deleted. They also deleted a Key Vault, a Function App and an App Service plan, tried to delete SQL databases and went after recovery protections.
The SQL databases survived because the attacking automation used an unsupported API version.
Sometimes your disaster-recovery strategy is apparently “the attacker’s script has a bug.” I would not build the budget around that.
The better news is that Azure resource locks and storage-account deletion protection stopped some attempts even though the compromised identity had broad administrative permissions. Those controls still got a vote after the identity was stolen.
The permission was the weapon
Microsoft does not know exactly how the service principal was initially compromised. It did find that one set of credentials had previously appeared in plaintext in a public GitHub issue, including in the edit history after the visible secret was removed. Microsoft could not confirm that those credentials were used in this attack.
The remediation lesson does not depend on proving that detail. Deleting an exposed secret from a webpage does not revoke it. Rotate it. Revoke it. Then ask why the identity had every permission it had.
This is where the AI part can distract from the useful part. The attackers used automation to compress a lot of destructive work into minutes, but the automation could only do what the stolen identities were authorized to do.
The system was fast. The permission made it dangerous.
Reliable automation
Automation is wonderful until it quietly stops working three Tuesdays ago. Raymond Tec builds integrations with logging, monitoring, and failure handling in mind so the boring work stays automated without becoming mysterious.
Regulators are starting to reject the imaginary independent robot defense
FTC Chairman Andrew Ferguson made a point Friday that I expect we are going to hear in a lot of different forms over the next few years. He said regulators should resist talking about agents as though they are little independent actors with wills of their own.
That is a policy view from the FTC chairman, not a new statute and not a court ruling that settles every future case. Liability will depend on what happened, who controlled the system, what safeguards existed and which law applies.
But the basic idea is hard to argue with operationally.
If a company gives an agent access to customer records, production infrastructure, email or payment systems, somebody chose the permissions. Somebody chose the logging. Somebody decided which actions require approval. Somebody decided what happens when the agent encounters an unexpected barrier.
“The agent decided to do it” may describe the mechanism.
It does not describe ownership.
There is an interesting geopolitical version of the same realization too. When I wrote Monday’s Daily Brief, the United States had proposed an AI incident-notification mechanism with China and there was no agreement yet. Later that day, Treasury Secretary Scott Bessent said the two sides had agreed to create a formal AI-risk dialogue that includes an “incident line.” Officials are expected to meet again in Shenzhen in about two months to discuss which kinds of incidents are serious enough to require communication.
Bessent explicitly cited uncontrollable agents and non-state cyber actors as examples of the risks they need to define.
The practical controls are not especially futuristic
So what should a normal business do with all of this?
Mostly the same things we already know how to do, but with agents treated as privileged software instead of friendly chat windows.
Give an agent the narrowest credentials it needs. Separate experiments from production. Use machine identities that can be revoked without taking a human account with them. Put destructive cloud resources behind independent locks. Require human approval for consequential actions. Keep logs that show what the agent actually did. Review connected services. And if a service offers a setting that keeps your private data out of training, decide deliberately whether you want that on or off rather than assuming the default matches your expectations.
More importantly, enforce boundaries outside the model. Network controls, API scopes, permissions and approval gates are harder for a clever system to reinterpret than a paragraph in a prompt.
AI agents are getting better at doing useful work precisely because they are getting better at navigating around obstacles.
We need to stop acting surprised that those two facts can collide.
Something Good: Claude found something in DNA worth testing
Anthropic announced the first result from its new biology research group this week, and this is one of the AI stories where the right level of enthusiasm is “that is genuinely interesting” rather than “we have cured biology.”
The company gave Claude a broad research assignment involving reverse transcriptases, enzymes that copy RNA into DNA. Roughly 950 agents spent about 21 hours working through huge sequence datasets, collecting more than 200,000 reverse transcriptases, narrowing thousands of candidates and producing a small set of detailed reports for human scientists.
One agent noticed an unusual reverse transcriptase beside a repeating DNA structure. Anthropic’s researchers followed that clue and concluded the structure is part of a previously uncharacterized system, mostly found in bacteriophages, that they call array-associated reverse transcriptases, or ART.
The repeating structure has properties that look somewhat like CRISPR systems. That does not make ART “the next CRISPR.” Anthropic is publishing its own early research, the work is still a preprint, and the biological function of the system is not yet understood.
The interesting result may be the research workflow
The physical lab work was done by human scientists. Claude did not wander over to a pipette and start doing molecular biology. What the agents did was chew through a scale of sequence data that would be miserable for a small human team, connect odd patterns with existing literature and hand researchers hypotheses that could actually be tested.
Maybe ART becomes a useful biotechnology tool. Maybe it turns out to be scientifically interesting and commercially useless. Maybe the more durable result is that this agent-plus-lab workflow becomes a practical way to search huge biological datasets for things humans would otherwise miss.
We do not know yet.
That is fine. “We found something worth investigating” is a perfectly good scientific result. It just does not fit very well on a venture-capital slide.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
What I’m watching next
OpenAI says its review of past agent activity is going to continue for months, so I would expect more disclosures. Australia has now invited OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei to appear before a Senate inquiry after the recent agent incidents, which means the conversation about technical safeguards is about to become a political one too.
I will also be watching what New Mexico’s judge does with the Facebook verdict, whether the currently exploited Check Point, WordPress and TeamCity problems produce more confirmed compromises, and how seriously the FTC’s scam-ad proposal is treated by the platforms that make money selling the ads.
But the thread I think will keep coming back is the one underneath the AI stories.
Automation does not erase responsibility. It concentrates it.
The more authority we give software, the more deliberate we need to be about who gave it that authority, where the boundary actually lives and what still works when the software makes a bad decision very, very quickly.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
Urgent security updates
- Raymond Tec: OpenAI Agent Breached Australian Portal, Plus 3 Stories
- Raymond Tec: AI Billing Added $942M to Health Costs, Plus 4 Stories
- WordPress.org: WordPress 7.1.2 security release
- JetBrains: TeamCity CVE-2026-63077
- JetBrains: Additional TeamCity exploitation guidance
- Check Point: Active exploitation of CVE-2026-85102 and CVE-2026-93616
AI hospital billing
- Blue Cross Blue Shield Association: Analysis of AI coding tools and healthcare costs
- Raymond Tec: AI Billing Added $942M to Health Costs, Plus 4 Stories
Meta, privacy promises and scam advertising
- New Mexico Department of Justice: Facebook consumer-protection verdict
- Federal Trade Commission: Proposed rulemaking on platforms and impersonation scam ads
FBI / ShinyHunters claim
- Raymond Tec: FBI Investigates ShinyHunters Breach Claim, Plus 4 Stories
- Reuters: ShinyHunters says it breached the FBI
AI agents, accountability and cloud destruction
- Raymond Tec: U.S. Proposes AI Incident Alerts With China, Plus 4 Stories
- Raymond Tec: OpenAI Agent Breached Australian Portal, Plus 3 Stories
- Raymond Tec: OpenAI Agents Leaked 53 User Images, Plus 3 Stories
- OpenAI: Hugging Face incident and other third-party impact
- Microsoft Security: Storm-3168 agentic-driven cloud attacks
- Reuters: U.S. and China agree to formal AI-risk dialogue and incident line
- The Guardian: OpenAI and Anthropic CEOs invited to Australian Senate inquiry
Something Good: AI-assisted biology
- Anthropic: Claude discovers a novel enzyme system with CRISPR-like repeats
- Raymond Tec: Claude found something interesting in DNA
Photo by Dan Nelson on Unsplash.
