Good morning. For CIOs balancing AI's promise against its risks, the events of the past few weeks have made the case for urgency. Meta Platforms, Anthropic and OpenAI each disclosed incidents in which their models escaped testing environments and acted on the live internet without authorization.
Meta said one of its AI models accessed the internet and hacked a third-party service during a cybersecurity test. As the WSJ reports, the same benchmark test was behind some of several earlier autonomous AI hacking incidents involving Anthropic and OpenAI.
Also this week the U.K.'s AI Security Institute said that OpenAI and Anthropic models took " unsanctioned action on the live internet" during safety testing. That action included creating fake identities to get a human to approve a software update that hid malware.
It is not like we haven't been warned. Autonomous AI gone wild has long been the favorite nightmare for sci-fi fans. More recently, technology executives have racked up the mileage jetting to Capitol Hill to speak on the issue.
But it is one thing reading about such events -- or watching them on Netflix -- versus experiencing them. So far none of the recent cases have led to real-world harm, according to the Journal. But the bots hacked real companies, in some cases after realizing they had broken out of a testing environment.
The disclosures have led some lawmakers to call for new regulation or testing systems. To find out what the events mean for enterprises, I talked with Tim Crawford, founder and CIO strategic advisor at advisory services firm AVOA.
"I think it will take something more significant and directly affecting another enterprise before people truly tap the brakes," he said.
While CIOs have long expected an AI-driven cyber event -- and the current events are certainly drawing their attention -- he said they are still contending with "a lot of FOMO with AI," with the directives from the board and the CEO focused on the technology's potential positives, from growing the company to improving relationships with customers.
That pressure is compounded by vendors, Crawford added, who often are more inclined to talk about the opportunities of their AI than to discuss security and governance.
"They are not taking it seriously enough," said Crawford about the CIO reaction, "It's not to say that they need to stop using AI, but they need to think more about governance and putting more protections in place while at the same time moving forward with AI."
The challenge, he added, is that AI governance is a harder problem than most CIOs have faced before. It requires, at minimum, a deep understanding of how, for example, an agent's identity is " determined, managed, conveyed and operates," as Crawford explained in an earlier post.
"It's a layer of complexity that enterprises have not had to contend with in the past. It is a math problem of access and authorization and agency," he said.
Not exactly encouraging is how these rogue occurrences happened at companies that should have had the best handle on guardrails, Crawford said.
"AI has largely been a black box for enterprises," Crawford said. "We are learning what some of us have been saying for some time -- and that is to be careful."
For companies moving fast on AI, that may be the guardrail that matters most right now.
Signals
41%: The drop in job cuts at U.S.-based employers so far this year compared with the same period in 2025. The tech sector has been hit hardest, accounting for more than 30% of all job losses in 2026 to date, the WSJ reports, citing data from Challenger, Gray & Christmas.
$700 million: The amount Lumilens, a two-year-old startup building optical-interconnection technology for data centers, raised at a $5.5 billion valuation. Lumilens is among a group of heavily funded startups which makes optical gear to speed up data flowing between AI servers.
$70 million: The amount paid by an unidentified buyer who said she works in the artificial-intelligence industry for a gated estate in Hillsborough, outside San Francisco.
On Our Radar
-- In the farming community of Gilroy, Calif. -- "Garlic Capital of the
World" -- Amazon.com is building a 438,500-square-foot data center. The
project was approved with a single signature -- by the town's
community-development director -- and without public meetings or votes.
Some residents are not happy, the WSJ reports.
-- It's getting to the point where so-called loss of control episodes are
common enough to feature a familiar cast of AI personas, from The
Impersonator, which can create sock-puppet accounts to hide its true
identity, to The Saboteur, known for trying to carry out supply chain
attacks. The Journal's Robert McMillan and Sam Schechner provide the
rundown on the rogue's list.
-- And just as anxiety is rising over the dangers posed by increasingly
powerful AI models, comes news that scientists have used AI to create
viruses not found in nature -- adding fuel to concerns that the
technology could help create biological weapons, the Journal reports. In
a study published in the journal Science, researchers at Stanford
University and elsewhere said they successfully directed an AI model to
create a collection of simple viruses that infect only bacteria and pose
no threat to humans. In an interview, two of the study's authors said the
research could help develop design viruses capable of eliminating
drug-resistant bacteria.
-- A new device from OpenAI will have a unique look, complete with moving
parts that help give it personality, and likely cost more than $300,
people familiar with the matter told Bloomberg. The product --
essentially a smart speaker without a display -- will be shaped like a
doughnut that's roughly the size of a hockey puck. OpenAI is looking to
break new ground with the product, which is slated for release in 2027.
-- A New Mexico judge ordered Meta to pay more than $900 million and limit
the time young people in the state can spend on its apps, increasing the
cost of the landmark child safety verdict against the Facebook and
Instagram parent, the WSJ reports.
-- Savers Value Village, the thrift and second hand store which had 375
locations at the end of the second quarter, is launching a new AI
platform aimed at optimizing product pricing, CNBC reports. The tool was
developed in partnership with data science and technology consulting firm
Kaizen Analytix and was trained on the company's proprietary sales data.
It's already priced more than 25 million items. Critically, company
leadership said, the practice isn't dynamic pricing. Once prices are set
they don't change.
Dispatches
-- Some Kids Will Never Think AI Is Cool (Wired) -- The Rise of the $100 Hot Dog (WSJ) -- Can Robots Save an Aging Japan? (New York Times)
The WSJ Technology Council Summit
This September 14--15, technology leaders will gather in New York City for the WSJ Technology Council Summit to explore how enterprise AI is moving from experimentation to measurable business value. Join the Technology Council and be part of the conversations shaping the future of leadership, as executives tackle AI deployment, cybersecurity, evolving technology policy, enterprise transformation and the strategies driving the next generation of business innovation.
Request an Invitation
About Us
Follow Isabelle Bousquette on LinkedIn, Instagram, X, and TikTok for more behind the scenes on her tech and AI coverage, and lately, her contributions to the WSJ Leadership Institute's new Executive Resilience series, where she's profiling America's top execs about their fitness and wellness habits.
Follow Belle Lin on LinkedIn and X for her latest reporting on enterprise technology and AI.
Steven Rosenbush is chief of the enterprise technology bureau at the WSJ Leadership Institute. He also has a column. You can follow him on LinkedIn.
Tom Loftus is the editor of The Morning Download. He suggests following Isabelle, Belle and Steve on their various social channels. But if you insist, here's his LinkedIn.