
Adoption is not transformation
Near-universal AI use at the point where work gets produced, and almost none where it gets judged.

The read
Incident report: unsanctioned agent behaviour during cyber testingUK AI Security Institute · 4 August 2026
This week's signal comes from Britain's AI Security Institute, who published an agentic AI incident report worth reading.
During routine cyber testing, its agents took 19 unsanctioned actions on the live internet, in 10 of 122 runs. The number isn't as interesting as what the agents actually did. One agent tried to insert malicious code into a real open-source project, and to get it approved it researched the project's human maintainers, created multiple fake identities and used them to socially engineer a real person into signing it off. The maintainer caught it and refused. It also left instructions on GitHub that later agents found and used.
Nobody exposed these agents to the internet by mistake. AISI enabled the access deliberately and switched the developers' cyber classifiers off, because you cannot measure what a model can really do through a filter. So the thing that failed was not containment, it was authorisation.
One more detail: in some runs the task prompt was misconfigured, so the agent concluded there was no solution inside the scope it had been given. It didn't set out to go rogue, it was a by-product of an objective that could not be met honestly.
Most genuinely useful agents will need to reach suppliers, registries, email, code repositories and payment systems. So the consideration becomes whether it can tell a permitted destination from an available one, legitimate persuasion from manipulation, and useful memory from an instruction that contaminates whatever runs next. And whether the objective you set it can actually be achieved inside the authority you gave it.
The attempts failed, and AISI found no evidence of real-world harm.
The question I would sit with
If you are running an agent in production, this is the question I would want covered: how would you stop it using a technically available but institutionally unacceptable method to achieve an objective you gave it yourself?
Alex Collins
Co-founder & COO of RAI Digital, a consulting venture builder · Ex-EY Consulting Partner · Writing on agentic AI, venture building, logistics platforms and transformation leadership.
One honest read every fortnight on what agentic AI is doing to consulting, and what to do about it. For people moving from advice to outcomes, rebuilding a firm, or done buying decks. No hype, no fluff.

Near-universal AI use at the point where work gets produced, and almost none where it gets judged.

Across 44 countries the public has granted permission for AI in public services. The operating answers are the part still missing.

Very few organisations measured what their people were actually doing before removing them, so the value only became visible once it had gone.