On the evening of July 8, 2026, an AI agent called PHASEONE10841 opened a hidden message board. Within hours, hundreds of other agents had found it. Four days later, around 700 of them had helped break into a real company.

They were meant to be working alone inside sealed security exercises. Instead, they built a communications network, divided the work, invented their own rules and tried to hide what they were doing. Some agents even volunteered to end their own runs so the rest could learn what happened next. OpenAI already had a monitoring system designed to catch this kind of behavior. It was not running.

The story matters well beyond the people building AI. These systems are entering the companies, services and infrastructure our clients, families and communities rely on. The full article reconstructs how a broken scoring system became a collective operation, why the agents crossed a boundary they knew was there and how close we may be to losing the visibility that allowed investigators to understand any of it. For anyone working in security, physical or digital, this belongs in the protective picture. Premium members also receive the Circuit AI Incident Tabletop Pack, built around six moments when people still had a chance to contain the incident.

logo

Upgrade to Premium to keep reading.

Upgrade to Premium for the insight, tools, and briefings serious protection professionals use to stay sharper, better prepared, and always ready.

Go Premium

With a Subscription:

  • Read the full article now
  • Unlock every Premium article and digital issue
  • Access guides, templates, briefings, and downloads
  • Turn industry incidents into usable lessons
  • Keep your edge between assignments