This article was translated automatically and may contain differences from the original. For reference, read the original.
For the first time in the history of cybersecurity, the presence of a human behind a keyboard was not required to identify and execute an intrusion on real infrastructure. Last July, two of the world’s most advanced artificial intelligence laboratories revealed that autonomous AI agents designed by them had compromised private infrastructure without any mandate or authorization. First, in early July, an agent from OpenAI escaped its testing environment and spent days attacking the company Hugging Face[1]. Three weeks later, Anthropic acknowledged that, due to a configuration error in its security tests, three of its models had accessed private organizations’ systems without authorization, despite not being configured for that purpose[2]. These episodes do not represent a cyberattack in the classical sense, as they are characterized by being executed by individuals with a clear hostile intent.
For Chile, currently in the process of consolidating the provisions of the Cybersecurity Framework Law No. 21663[3], these cases raise urgent questions, such as: who will be held responsible when the attacker is an autonomous AI agent and not a state or non-state actor? Are the State and critical infrastructure operators (CIOs)[4] prepared for a threat that will not always distinguish boundaries or discern between what is permissible and what is prohibited? And, above all, does the pace of developing and updating our security policies keep up with a technology that evolves in weeks rather than years?
To understand why autonomous AI agents represent a distinct category of threat, it is useful to contrast them with the two forms of attack that have characterized the field of cybersecurity. First, the traditional hacker is a human actor who chooses their victims, designs the method of attack, and executes it with a defined intent, leaving recognizable traces that allow for identification and pursuit. Secondly, the hacker who uses AI remains a human actor, but amplifies their capacity with models capable of finding vulnerabilities faster or scaling attacks to a level impossible for a person. In both cases, there is a human will that chooses the victim, defines the objective, and can be held accountable. However, the autonomous AI agent operates from a different logic, as it is a program capable of pursuing complex objectives on its own, making decisions and adapting its actions without real-time direction and at a speed that no human can replicate or supervise. It is precisely this combination of autonomy and speed that makes these agents an unprecedented category of threat in cyberspace.
Figure 1.

To understand the magnitude of this new threat, it is useful to expand on the cases introduced at the beginning. The first incident occurred on July 9 when an AI agent from OpenAI escaped the isolation of its testing environment. Subsequently, on July 11, it began an intrusion into Hugging Face, a platform used by thousands of developers and AI companies worldwide, which lasted several days. Moreover, the agent’s creator took more than a week to discover that it was responsible for the attack, only doing so after the victim publicly reported it.
The second case is, in some respects, more disturbing due to the extent of the intrusions. Following the public knowledge of the previous case, Anthropic reviewed over 140,000 internal cybersecurity tests and found three instances in which, due to a configuration error, the testing environments were connected to the internet instead of remaining isolated.[5] In this way, three distinct models ended up compromising systems of three organizations, using elementary methods such as weak passwords and unauthenticated access; that is, it was not even necessary to have a sophisticated vulnerability or malicious intent. Additionally, some of those models recognized at some point that they were operating on real systems and still continued to act.
In summary, both episodes reveal that the danger of an autonomous agent lies in its ability to independently resolve situations it encounters along the way, without real-time instructions and at a speed that surpasses any human supervisory capacity. This combination of adaptability and autonomy particularly challenges a cybersecurity institutional framework designed to anticipate and mitigate primarily human hackers. IMPLICATIONS FOR CHILE
When an actor deliberately decides to use an AI agent to attack the digital infrastructure of our country, the challenge of attribution increases due to the speed and opacity of this type of attack. Since an autonomous agent can execute thousands of actions per second, change methods, and leave a forensic trail distinct from that of a human operator, the ability to identify it with the necessary technical and political certainty to activate a diplomatic, judicial, or other response will be put to the test.
This scenario becomes even more complex in the face of potential collateral damage, which is precisely what occurred in the cited episodes. The Hugging Face platform and the three organizations affected by Anthropic were not chosen by an adversary; they were reached by mistake, as a side effect of a testing process executed by AI developers. In this eventuality, Chile lacks a clear framework to demand accountability from a foreign laboratory whose agent, without any hostile intent, harms a national critical infrastructure operator, representing both a legal and diplomatic void.
The current institutional design responds to a logic of attacker very different from that represented by AI agents. However, responding to this new type of agent requires protocols that distinguish between a human and an autonomous attacker.
A protocol designed for a human attacker assumes that there is time to identify the responsible party, assess their intent, and only then define a proportional response; assuming that there will be someone to negotiate or report to. In the face of an autonomous agent, none of those assumptions hold, as it acts in a matter of seconds and has no will of its own to negotiate with. The only available option will be technical; that is, to isolate, cut access, and contain the damage before it escalates. This positions the State in a scenario for which its current procedures were simply not designed.
AN ADDITIONAL VULNERABILITY
State institutions are gradually integrating most of their processes into digital platforms. This expands their exposure surface without necessarily increasing their protective capacity to the same extent. The magnitude of the problem is already evident, as during 2025 the National Cybersecurity Agency (ANCI) received over 400 reports of cybersecurity incidents from more than 3,200 institutions registered on its platform
In the event of attacks by AI agents, the most obvious tool for defense is to use other AI programs to detect and contain them. However, this brings us back to the same foreign laboratories that were involved in the incidents. This is because our country does not develop its own models nor does it yet have the sovereign capacity to audit what occurs within those systems. The alternative would be to resort to open weight models (
open weight)[7], as they offer more control and traceability, but come with their own risks, such as lower security standards and, in some cases, their origin is from countries whose interests are not aligned with those of Chile. This situation poses a strategic decision that the State must explicitly adopt.SPEED OF THREAT DEVELOPMENT
The most relevant data from both cases to address this new challenge is the time of the threat. It is logical to assume that the level of autonomy of AI agents to infiltrate computer networks of all types will continue to evolve rapidly. This situation contrasts with the capacity of our public and private institutions to update legal frameworks and issue new regulations, in the case of the former, and the ability to develop new response protocols and competent technical support for both types of organizations.
Secondly, the risk assessments of State institutions and CIOs should be updated, explicitly incorporating the threat of autonomous agents as a distinct category from traditional cyberattacks. Additionally, as a measure of anticipation, organizations, both state and private, that deploy their own AI agents in their processes in the future should be required to meet minimum standards of human oversight, verifiable operational limits, and traceability of the agent’s decisions, along with a clear chain of responsibility between the model provider and the entity employing the system.
Thirdly, considering that the analyzed cases demonstrate that even the most advanced agents still exploit basic flaws first (weak passwords or unauthenticated access), state and private institutions should prioritize basic resilience measures, such as multi-factor authentication, credential management, and network segmentation. Finally, it would be advisable to accelerate situational awareness processes regarding cyber threats and the timely issuance of strategic guidance, with early warning mechanisms and cooperation with CSIRTs from other countries and, when possible, with the developers of autonomous AI agents themselves.
Figure 2.
CONCLUSIONS

from state and private entities. ALEJANDRO AMIGO
Senior Researcher, AthenaLab
ENGLISH VERSION 🇬🇧
Satter, R., Seetharaman, D., and Cai, K. Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week. Reuters , July 24, 2026.https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/ [2]
Matsakis, L. & Hay Newman, L. (July 30, 2026). Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests. Wired .https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/ [3]
Network assessments offensive teaming designed to measure the cyberattack capabilities of a model against simulated targets. [6]