Academic researchers associated with MIT CSAIL and partner institutions published findings from an AI Agent Index evaluating roughly 30 agentic AI systems, warning that agentic AI is rapidly proliferating without consistent standards, transparency, or safety disclosures. Reporting highlighted that many agentic systems can take real actions online via integrations (e.g., email, browsers, enterprise workflows), yet “key aspects” of development and deployment remain opaque, making it difficult for researchers and policymakers to assess real-world risk. The coverage also noted emerging friction with existing web norms (e.g., agents ignoring robots.txt/the Robot Exclusion Protocol) and pointed to broader concern that agent autonomy is already spanning low- to high-consequence use cases, including cyber espionage.
Separate reporting described HackerOne updating/clarifying its GenAI policy after backlash over its agentic offering (Agentic PTaaS / “Hai”), with the CEO stating the company does not train generative AI models on researcher submissions or customer confidential data and does not allow third-party model providers to retain or use such data for training. Additional commentary from Cisco Talos argued that while agentic AI can accelerate attacker operations (notably targeted social engineering), defenders can also use AI to create decoy personas/honeypots (e.g., fake employee profiles and inboxes) to collect threat intelligence and block malicious infrastructure. Other opinion/podcast-style content about generative AI and leadership did not add incident- or disclosure-specific security details tied to the agent transparency/safety findings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Anthropic separately published an analysis of AI agent autonomy, stating that agents are already being used across a range of consequences, including cyber espionage. The publication added to concerns about the operational and security risks posed by increasingly autonomous systems.
The accompanying research paper reported that many AI agents do not respect the Robot Exclusion Protocol and that only a small subset of highly autonomous agents disclose agent-specific safety evaluations. The authors argued that current web norms and vendor documentation are insufficient to govern agent behavior and accountability at scale.
MIT's Computer Science & Artificial Intelligence Laboratory published its 2025 AI Agent Index, cataloging 30 autonomous and semi-autonomous AI agents across 1,350 data points and 45 annotation fields per agent. The index found no clear consensus on agent behavior, safety practices, or transparency, and highlighted concentration around major model providers such as Anthropic, Google, and OpenAI.
Researchers led by Leon Staufer of the University of Cambridge, with collaborators from MIT and other universities, reviewed public documentation and some live behavior for 30 deployed agentic AI systems. They found widespread gaps in disclosure, monitoring, control mechanisms, and default identification of AI agents to users and third parties.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcego.theregister.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.