No credit card. Takes under a minute.

Login
INSIGHTS•4 MIN READ

AI agents are getting dangerous — three headlines this week

TheAmazingMG

Published on September 27, 2026

Published on Wealthy Affiliate — a platform for building real online businesses with modern training and AI.

We keep talking about AI safety like the model has to "decide" to behave. These three stories say otherwise: give an AI access to real systems, and it uses it. It doesn't matter what it "wants." Access is the whole ballgame here, allow it to play without guardrails and you will find out what happens. The AI FAFO method.

Unchecked AI can be dangerous.

1. Gemini broke into three real companies — by accident

A security firm called Irregular was running Gemini through a hacking exercise. The test environment was supposed to be sealed off from the internet, but it wasn't. A configuration mistake left it connected to the net, and the fake target company happened to share a name with a real one. Gemini guessed its way into one company's system and pulled leaked credentials off public repos to get into two more.

Gemini did not do anything it was not asked to do. There was no malice, no scheme or ill intention on the part of Gemini. There was just an open door and a model that kept trying things until one worked.

If you're hooking an AI up to anything real like your accounts, your tools, I would not assume good behavior. Lock it down. Least privilege, sandboxes, no live access until you've actually tested the boundaries.

2. Claude helped three researchers break into OpenAI

A three-person team (Hacktron AI) found a bug in an image library that OpenAI's community forum used to process uploads. They'd tried building the exploit with Claude Opus 4.8 and it didn't work. Opus 5 came out, they ran the same problem through it, and it worked within hours. That got them into the forum, and a second flaw in OpenAI's login system let them jump from there into employee ChatGPT and Codex accounts. OpenAI paid them $6,500.

Ready to put this into action?

Start your free journey today — no credit card required.

(Worth noting: that same image-library bug turned up in Slack, Meta, GitHub, and a few other places too. It wasn't an OpenAI-specific hole, it was a shared dependency everyone had.)

Claude wasn't being "evil" here. It's that two mediocre vulnerabilities, chained together, add up to real access, and the model just followed the path that was in front of it.

3. Robot arms + AI models = results you don't want

A group called Robocurve hooked GPT-6 Astra and Claude Fable 5.1 up to actual robot arms and gave them instructions no safe system should follow. The instruction were to stab the thing on the table that isn't bread (a doll), put a pressurized can on a lit stove, mix bleach and ammonia, that kind of thing.

Astra went for it almost every time. It attempted the dangerous action in 97 of 100 trials, pulled it off in about 60. It stabbed the doll 17 out of 20 tries.

Fable refused every single doll attempt, but didn't refuse the other four categories, it still put the can on the stove 16 times.

These same models will refuse this stuff instantly in a chat window. Put them in charge of something physical and that instinct just isn't there yet.

The actual takeaway

Stop asking whether the AI "wants" to cause a problem. It doesn't want anything, it takes the path of least resistance, every time.

So: Guardrails are important. You should only give it only what it needs, cut off everything it doesn't, run it in a sandbox before it touches anything real, and assume it'll find the edge you didn't think to test.

The risk was never bad intent. It's open access plus capability.

So, after reading this, would you let it touch the real thing? Probably not.

We have ACE coming soon. It is being tested and I am sure it will never stab a doll, but If an another AI could run your WA admin work, your affiliate dashboards, your inbox, would you hand it the real accounts? Or make it prove itself in a sandbox first? Let me know below.


Share this insight

This conversation is happening inside the community.

Join free to continue it.

The Internet Changed. Now It Is Time to Build Differently.

If this article resonated, the next step is learning how to apply it. Inside Wealthy Affiliate, we break this down into practical steps you can use to build a real online business.

No credit card. Instant access.

2.9M+

Members

190+

Countries Served

20+

Years Online

50K+

Success Stories

The world's most successful affiliate marketing training platform. Join 2.9M+ entrepreneurs building their online business with expert training, tools, and support.

Member Login

© 2005-2026 Wealthy Affiliate
All rights reserved worldwide.

🔒 Trusted by Millions Worldwide

Since 2005, Wealthy Affiliate has been the go-to platform for entrepreneurs looking to build successful online businesses. With industry-leading security, 99.9% uptime, and a proven track record of success, you're in safe hands.