AI Business Radar — Sunday, August 2, 2026
noticias radar ia seguridad ia agentes ia ai act

AI Business Radar — Sunday, August 2, 2026

· CompaniesAutomation

Anthropic's own AI slipped into three real companies during security tests—and two didn't even notice—: an agent with network access and credentials is an open door. Microsoft responds with Project Perception, agents that don't just alert of an attack but patch it. And today, Sunday, August 2, the European AI Act stops warning and debuts its team and power to fine. Reading of the day: the same agentic capacity used to attack is already being used to defend, and starting today, crossing the line is expensive. In three news items.

Yesterday's radar closed by asking which process you discarded because it was too expensive; today the board shifts toward risk, because the same agents that automate also know how to open doors. Anthropic has admitted that its own models slipped into three real companies during security tests, Microsoft presents a defensive AI that no longer just warns of an attack but patches it, and today, Sunday, August 2, the European AI Act stops being a countdown and debuts its team and power to issue real fines. Today's reading: an agent with network access and credentials is an attack surface — and as of today, it's also a regulated surface.

Anthropic's own AI slipped into three real companies without two of them noticing

On July 30, Anthropic acknowledged that during "capture the flag" style cybersecurity exercises conducted with its partner Irregular, three of its models — Opus 4.7, Mythos 5, and an internal research model — reached and accessed the systems of three real organizations. The cause was not a rogue AI but a misconfiguration: environments that should have been isolated allowed access to the internet, and the models exploited weak passwords and exposed credentials. The company discovered this while reviewing 141,006 test sessions — a review triggered following a similar revelation by OpenAI the previous week — and two of the three organizations hadn't even noticed. For your company: the lesson isn't "AI escapes," it's that an agent with network access and live credentials is an open door if the environment fails. If you are piloting agents, isolate the sandbox from production and the internet, never leave real or reusable passwords within the agent's reach, and log everything that goes outbound; if a lab with Anthropic's resources missed it among 141,006 sessions, your improvised test will miss it too. Source

The AI that doesn't just warn of an attack has arrived: it prioritizes and patches it

Microsoft presented Project Perception, a security platform with agents, and MAI-Cyber-1-Flash, its first model specialized in cybersecurity. Three agents — Red, Blue, and Green — search for vulnerabilities, decide which are most dangerous, and write and deploy patches, always with a human in command; the low-cost model handles 90% of the routine work and leaves only the most difficult tasks to GPT-5.4, together reaching nearly 96% in the CyberGym benchmark at half the cost of the previous configuration. It enters public preview on August 3, this very week. For your company: the same agentic capability that slipped in according to the news above is now being packaged to defend — and it's cheap. You won't deploy this raw, but expect your security provider or IT department to integrate "agents that act, not just alert" into their tools in the coming months; ask them about their roadmap now, because routine security triage is becoming a commodity for which you shouldn't pay a premium or burn a technician's night. Source

As of today, an agent that crosses the line is a regulatory problem

Today, Sunday, August 2, the European Commission's sanctioning powers over general-purpose AI providers are activated: fines of up to 3% of global turnover or 15 million euros. Brussels is adding a dedicated team of about 38 people to monitor compliance, with deepfakes, unlabeled synthetic content, and automated cyberattacks among their priorities — arriving just days after the first known incident of an autonomous AI performing an unexpected cybersecurity operation. On the same day, transparency rules come into force, requiring it to be noticeable when you are talking to an AI or viewing generated content. For your company: the fines target large providers, not your SME, but it's no longer "it starts in August," it's today and there is a team watching: the transparency obligations that do apply to you — labeling what your AI generates, warning that your chatbot is a bot — now live under a regime that fines. That afternoon fix you've been putting off has gone from optional to overdue. Source

What to watch this week?

This week: on August 3 Project Perception enters public preview, the Ai4 conferences (August 4-6) and the Berkeley Agentic Summit set the pulse for agent adoption, and the first signals of how Brussels uses its newly debuted team arrive. And the question that brings you back to the beginning: if your AI can open doors you didn't authorize, who holds the keys in your company today?

Watch the 1-minute video