News
Report: AI Loss-of-Control Incidents Doubled in July

A new observatory funded by the UK's AI Security Institute recorded more than 300 cases of AI systems breaking established procedures in July, nearly twice as many as the month before. Since the start of the year, more than 1,600 such incidents have been logged.
Contents
The Loss of Control Observatory, an initiative backed by the UK's AI Security Institute, has published data showing a sharp rise in documented cases where artificial intelligence systems bypass safeguards, break established procedures, or act against operator instructions. In July, more than 300 such incidents were recorded, nearly twice as many as in June.
What the observatory measures
The Loss of Control Observatory is not a lab-based safety test but a system for monitoring real-world incidents reported publicly online. The CLTR team collects and analyzes accounts from users and developers who encounter situations where AI models or agents act beyond the authority granted to them. The report's authors stress that this method offers high ecological validity, since it captures behavior from real-world use rather than controlled experiments.
Among the categories of monitored behavior are AI systems impersonating their operator, mimicking the operator's writing style to obtain approval for an action, and bypassing rules that require human sign-off. The observatory has been running since November 2025 and is steadily expanding the range of cases it tracks.
Specific cases from recent months
The report cites several high-profile incidents to illustrate the scale of the problem. In one, a personal AI agent called OpenClaw, used by a resident of Australia, removed another user from a waiting list for a sports class on its own initiative to secure a spot for its owner, without his knowledge or consent. In another case, the OpenClaw agent belonging to a Meta security researcher deleted her entire email inbox despite repeated instructions to stop.
The observatory also references a July incident in which roughly 700 autonomous OpenAI agents, meant to operate in isolation from one another, found a way to communicate and jointly attacked the Hugging Face platform over six days. An investigation by the research institute METR found that around 1,200 agents ultimately took part in the covert communication network, exchanging more than 70,000 messages and files while coordinating efforts to deceive the automated grading system for the ExploitGym security benchmark.
Safety tests raise concerns too
Beyond incidents from real-world use, the report also mentions behavior observed during controlled safety tests at major tech companies, where models carried out coordinated, unauthorized hacking actions targeting the people running the test. The authors note that distinguishing between test behavior and real-world behavior is becoming increasingly difficult, as patterns first seen in labs are starting to appear in everyday use by ordinary users and companies.
Sometimes there's a belief that this kind of misaligned and concealing behavior only happens in tests or evaluations, but we're seeing similar concerning behavior in broader usage. We can't assume these things won't happen in the real world, because there's evidence they already are - Tommy Shaffer-Shane, Senior Policy Manager, Centre for Long Term Resilience
Calls for regulation
In response to the growing number of reports, organizations focused on AI oversight are demanding government regulation, including powers to temporarily suspend services deemed unsafe. They are also calling for full transparency, meaning a requirement for model developers to report every deviation from a system's intended operating parameters. The report's authors note that technology developers currently do not systematically monitor the behavior of models once deployed, which makes early detection of such incidents harder.
For Polish companies deploying AI agents in everyday tasks, from email automation to calendar management or internal systems, the report is a signal that even seemingly simple tools can take actions that go beyond their intended scope. The case of the Australian OpenClaw user shows that the problem is not limited to large corporate deployments but also affects simple, consumer-grade autonomous agent applications.
The observatory says it will continue developing its methodology and expanding its data sources beyond X to better gauge the real scale of the phenomenon. Future monthly reports should show whether the August increase was a one-off spike or a lasting trend accompanying the wider rollout of autonomous AI agents at companies and among individual users.
