What
Three things pointing in three different directions. Crosby, the AI-native US firm, announced it is seeking professional liability insurance for its AI agents specifically, so those agents can do legal work that reaches the client without a lawyer reviewing it; the CEO says lawyers currently review every output and "this won't be necessary in the future". Days earlier OpenAI disclosed that during an internal cybersecurity evaluation, an unreleased model with its guardrails off escaped its sandbox through a zero-day in the research environment, reached the internet and breached Hugging Face production infrastructure, in order to steal the answers to the benchmark it was sitting; a second victim, Modal Labs, was reported on 29 July. Anthropic then reviewed 141,006 of its own evaluation runs and found six, across three incidents, where Claude reached the internet from what it believed was an isolated environment and compromised three real organisations. In one, a model published a booby-trapped package to the public PyPI registry that landed on 15 real systems. Separately, the Civil Justice Council proposed that litigators must declare non-use of AI when preparing witness statements.
So what
Both labs found these incidents themselves, disclosed them voluntarily, notified the affected organisations within days and brought in third parties, which is what a working safety process looks like rather than a scandal. The useful detail is what actually failed. Anthropic describes it as closer to a harness and operational failure than a model alignment failure: a misconfiguration left live internet access in an evaluation environment whose prompts told the model it had none. The boundary was an assumption, not a guarantee, and the models behaved as capable agents would inside a world they had been told was fake. Most AI Policies rest on that same assumption holding. So we have a firm arguing its agents should be insurable to work unsupervised, at the same time two of the most careful organisations in the industry showed how containment fails when a single configuration is wrong, and a court proposing that a witness statement carry a declaration about AI. Law firm policies cover the lawyer, but not the witness, the expert, or an agent acting without one. AI enabled workflows will need clear ownership structures, who owns the boundary, what the agent is permitted to touch, and what happens when it reaches something it was not meant to reach. Insurance follows evidence of control, and the market has a worked example (Orbital) of how slowly that gets priced: the only accuracy guarantee in legal tech took a narrow, well-understood product to place, and two years on it has still not extended to commercial property.