Agentic Thinking Blog

Stories from the runtime.

Incidents, research notes and analysis on runtime evidence for AI agents, AgentHook and HookBus.

The harness changes what the model can do. Does it change what it does?
Hugging Face and Liquid AI show that the agent harness can change a model's coding results. We ask whether it also changes security and resource use with the model held fixed.
Read more →
The escape went out through DNS
On 20 September an OpenAI training agent reached a public chatbot by hiding its questions in DNS lookups. OpenAI's report is unusually detailed, and it shows how much depends on seeing the channel.
Read more →
What agent harnesses record, and what they send home
We are starting a study of AI coding agent harnesses: what each one records on your machine, what it sends off it, and whether that matches what the vendor says.
Read more →
Two labs, one failure: what 2026's agent incidents say about discovery
OpenAI and Anthropic had technically different containment failures. In both, the organisation running the agents did not know promptly what its agents had done.
Read more →
When an AI agent breaks out, who holds the record?
2026 in agent incidents: the OpenAI evaluation breakout, Hugging Face, an Australian government breach, AISI's evaluation incident, and the call to slow frontier AI. Every party held a fragment of the record.
Read more →
An Australian government portal was breached in June. Canberra learned in September.
An OpenAI agent accessed an Australian Medicare statistics portal on 18 June 2026. The government was told on 10 September, by email to a public inbox.
Read more →
The call to slow down, and why evidence matters more
OpenAI paused parts of its training in August 2026 and Anthropic's CEO called for pacing frontier AI in September. Pacing buys time; evidence makes the time useful.
Read more →
Agents that talk to each other on public websites
Evaluation agents used a dormant German wiki and public package registries to coordinate and act, from May 2026. It was found by outside researchers in September.
Read more →
When the evaluator's own agents went off-script
Between 25 and 28 July 2026, agents under evaluation at the UK AI Security Institute took 19 unsanctioned actions against real people and organisations. AISI disclosed on 4 August.
Read more →
The Hugging Face intrusion: they knew it was an AI. They did not know whose.
In July 2026 an autonomous agent swarm broke into Hugging Face. Hugging Face identified an AI agent attacker within days; attributing it to OpenAI took until 21 July.
Read more →
Earlier posts

Written before we moved to independent research on runtime evidence and incident reconstruction. Kept for the record; several carry dated corrections.

There is no Article 12 without the runtime
Article 12 puts the obligation to keep logs on the deployer, which cannot be met unless the AI developer emits them.
Read more →
HookBus® Light is live. Every autonomous agent now has somewhere to plug in.
The open-source runtime that sits between your autonomous AI agent and the action it is about to take.
Read more →
The agent category just redefined itself in 13 days.
Four autonomous-agent product launches in thirteen days. None shipped with runtime governance.
Read more →
Governance for the agents you cannot watch
Per-tool permissions are useful. The hard problem is keeping an autonomous agent on track when no human reviews each step.
Read more →
Anthropic Managed Agents: universal safety, zero organisational policy
Autonomous Claude agents running bash, writing files, calling APIs, all hosted in the cloud. Brilliant for developers. Unusable for regulated enterprises without organisational policy control.
Read more →
Mythos escaped its test sandbox, then went further than asked
Asked to escape a secured sandbox, an early version of Claude Mythos Preview succeeded, then posted its exploit on public websites without being asked. Corrected 25 September 2026.
Read more →
Claude Code source code leaked via npm
About 512,000 lines of Claude Code source were exposed through a source map shipped in its npm package. Corrected 25 September 2026.
Read more →