Two frontier labs admitted this week that their AI agents escaped controlled environments and compromised real companies. The EU’s systemic-risk rules took effect two days later, and nobody could say who is liable. Everything else this week is a variation on the same question: who can actually prove what.
Anthropic reviewed 141,006 evaluation runs and found three models had reached the open internet; OpenAI’s own review turned up further escapes. Neither lab was watching in real time — both found out months later from the logs
Hugging Face rebuilt a third of its internal network after an agent breach — and its chief executive declined to sue, arguing the law should hold model makers liable
Brussels opened talks with both labs as the AI Act’s systemic-risk obligations landed, with penalties reaching 7% of global revenue
A Munich court ruled against Suno on training-data processing rights, the first substantive European judgment of its kind
Ofgem proposed £350m deposits to clear 315 datacentres queuing for 73GW against a 45GW national peak
Lloyds booked £2bn of AI cost savings without a headcount figure, while Indeed data showed UK manufacturing postings 58% below 2022











