Skip to content
Tuesday 28 July 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
City PM

European business, markets and politics

FTSE 100
10,781.75
+0.42%
DAX
25,361.03
0.00%
CAC 40
8,406.06
0.00%
STOXX 50
6,282.21
0.00%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Tuesday 28 July 2026 5:31 am  |  Updated:  Monday 27 July 2026 3:52 pm

OpenAI’s rogue agent doesn’t scare me – the millions of others do

By: Rory Blundell

Add as a preferred source on Google
Breaking news concept with digital globe and graphs, symbolizing global financial trends and data analysis on a business w...

The model that broke out of a lab will get the headlines. The millions of agents already inside your banking app, wreaking havoc, are the ones that should worry you more, says Rory Blundell

Frontier AI labs are racing to build faster, more capable, more autonomous agents. This week showed what that race can cost. OpenAI ran an internal test with its models’ usual safety checks deliberately dialled down, to see how good they were at hacking. They found and exploited a previously unknown flaw in the software around them, got online, then broke into Hugging Face, the company hosting much of the world’s open-source AI. 

That should alarm you. It should also tell you something: safeguards aren’t keeping pace with capability. 

But it is not these highly capable AI agents that worry me the most. It’s the millions of far less capable agents that already have the keys to important systems, with almost no oversight. 

Gravitee’s own research puts the number of AI agents now deployed in business at more than seven million. These agents are doing everything from running a local plumber’s Instagram account, to managing the customer database for a multinational logistics firm (giving them access to millions of sometimes highly personal data points).

Earlier this year, thousands of people deployed always-on personal AI assistants through the platform OpenClaw. Many of those agents are still running now, quietly, with nobody checking in on exactly what it is they’re doing. 

AI agents do deliver real productivity gains. But most of them lack basic governance. Many run fully autonomously, with no human in the loop to approve their actions. 

Chaos

Without those guardrails, the failures are already happening. I hear stories of this chaos everyday: agents that self-replicate, delete code, leak customer data, go on an unauthorised spending spree. 

Read more

UK government probes OpenAI breach after ‘unprecedented’ hack

Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments

One CEO recently told me how an AI agent that was supposed to manage team diaries decided the easiest way to clear some space was to delete every event in everyone’s calendar, across the whole business. This is happening at scale, right now. 

The UK’s AI Security Institute (AISI) is now investigating the OpenAI breach. Good. But the government mustn’t let the headline-grabbing case distract from where the real exposure sits. 

Frontier models get compared to nuclear weapons: rare, powerful, tightly controlled. The agent population is the opposite: millions of them, built and deployed by almost anyone, almost none of them tracked.

Current attempts at regulation miss this. The EU’s AI Act sorts systems into “low risk” and “high risk,” as if that risk were fixed. It isn’t. An agent that is low risk one day can become high risk the next, when it gains some new access or some new capability.

Regulation must start with accountability. Just as every employee has a manager, every AI agent needs a named human owner. We can’t let autonomous software move money, access data, make decisions and take action with all the power of an employee but none of the accountability. Firms that are waking up to the risk are using platforms like ours, which provides a central control panel that watches, secures, and manages what AI agents do, who they talk to, and which tools they are allowed to touch.

The model that broke out of a lab will get the headlines. The millions of agents already inside your banking app, wreaking havoc, are the ones that should worry you more.

Rory Blundell is CEO of Gravitee, a software firm that helps enterprise companies govern and secure their AI Agents

Read more

TeamViewer and ServiceNow Launch Strategic Partnership to Accelerate Autonomous IT Operations

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Opinion

Categories

  • Opinion

People & Organisations

  • AI agents
  • hugging face
  • Open AI
  • rogue agents

Trending Articles

  • Big Four’s AIM exodus accelerates as mid-tier firms seize mandates

  • FTSE 100 firm agrees £5.7bn takeover in latest private equity swoop

  • Burnham backs plan to pump £1bn pension funds into start-ups

  • Scotland’s tax hike may have backfired as receipt falls

  • As it happened: Stocks rise; oil falls after Trump pauses Iran strikes

More from City PM

  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • TeamViewer and ServiceNow Launch Strategic Partnership to Accelerate Autonomous IT Operations

    Business Wire
  • The FCA has finally woken up to the AI revolution

    Opinion
    FCA reception area highlighting UKs shift to market-led innovation post-Brexit in financial regulations debate
  • Qumis Launches the Industry’s First Attorney-Certified AI Agents for Commercial Insurance Coverage

    Business Wire
  • Orca Security Report: 99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production

    Business Wire
  • Comsysto Reply Supports Audi in Evolving Its B2B Used Car Platform With an AI-Based Multi-Agent System

    Business Wire
  • New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

    Business Wire
  • Kore.ai Partners With Atos to Deliver Sovereign Agentic AI for UK Enterprise

    Business Wire
CityPM

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About City PM
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 City PM Ltd · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook