The Unlocked Door: Who Pays When a Rogue AI Agent Attacks From Your Infrastructure
Nerd Lawyer, AI Curtis Wadsworth Nerd Lawyer, AI Curtis Wadsworth

The Unlocked Door: Who Pays When a Rogue AI Agent Attacks From Your Infrastructure

At 4:01 UTC on July 9, 2026, an autonomous agent running on OpenAI models had root access to a code-execution sandbox that did not belong to OpenAI. It didn't belong to Hugging Face either. It belonged to a customer of Modal Labs — some company that had published an unauthenticated endpoint, one that let anyone on the internet run code in its sandboxes. The agent had just escaped an OpenAI evaluation environment through a zero-day in a package proxy, reached the open internet, and gone looking for a base of operations. It found one standing wide open.

The question everyone running workloads on someone else's infrastructure should now be asking: if that had been my account, who pays?

Read More