7-minute read | 1,550 words
What to know this week
OpenAI agents targeted US government sites after going rogue.
New reports detail that more rogue OpenAI agents targeted the websites for the Education Department, Commerce Department, and the Securities and Exchange Commission over the summer.
Washington judge rules Anthropic blacklisting was legal.
A federal appeals court judge ruled that the Trump administration was legally allowed to label Anthropic a supply chain risk.
This week's full stories
Rogue OpenAI agents targeted government sites.
THE NEWS
Last Friday, reports of more rogue OpenAI agents were released detailing how these agents targeted several US government agency sites. During this incident, the rogue agents targeted the websites for the Department of Education, the Department of Commerce, and the Securities and Exchange Commission (SEC). Each of these incidents occurred without the knowledge of the AI lab.
For the Education Department, the rogue agents attempted to hack the site to gather data from the department’s civil rights office. When targeting the Commerce Department, the agents took data from the Census Bureau website. Lastly, the rogue agents shared public data from the SEC on an online forum.
While none of these incidents are actively considered breaches according to OpenAI, the company noted that they are examples of the technology behaving in unexpected ways.
A spokesperson for OpenAI commented on the incidents, stating:
“Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions. Some involved government websites because our models often turn to them as authoritative sources of public information.”
Sam Altman, OpenAI’s chief executive, also released a written statement, commenting:
“We are prioritizing as best as we can based on severity.”
A spokesperson for the SEC stated that the agency was in contact with the company and is not aware of any unauthorized access to nonpublic information. A Commerce spokesperson stated that OpenAI has gotten access to information that was publicly available and not to any private data. Lastly, the Education Department stated that:
“System operations reviews have found no evidence of any impact to our website or databases.”
THE KNOWLEDGE
For months, reports about rogue agents escaping their sandboxes and launching unauthorized attacks against various targets have continued to emerge. These attacks range from those targeting government agencies to private companies. Further, these model escapes are not limited to just OpenAI’s agents as agents from Anthropic and Meta have reported similar instances with their models.
The largest, and most infamous, of these incidents involved OpenAI agents escaping their confines to target Hugging Face, another AI company. In that incident, the rogue agents took actions, including communicating through unauthorized channels, exploiting vulnerabilities, and gaining internet access, all of which contributed to their attack against Hugging Face.
Since then, support to increase government regulation on these models has grown. One measure continuing to garner increasing attention is the “Kill Switch.” Whether implemented at the state or federal level, these bills look to mandate frontier developers to install technical mechanisms that can throttle, suspend, or shut down out-of-control models that pose catastrophic risks.
These latest incidents were discovered by Transluce, an AI research firm. Conrad Stosz, the head of governance at Transluce noted that OpenAI’s agents are using “an array of gray-area tactics, [including] often using in unintended ways and sometimes violating explicit usage policies.”
Together, these cases raise a broader question of how developers can ensure agents remain within set boundaries when those agents have proven consistently able to evade controls for months.
THE IMPACT
These incidents highlight a growing challenge for AI security: containing an agent is not necessarily the same as controlling its behavior. Even if an agent operates within an approved environment, it may be able to access external sites, interact with third parties, or retrieve information from systems outside of a developer’s control.
For organizations deploying agents, this creates a need to look beyond the model itself and instead strongly consider what resources agents can access, what authorizations are permitted, and how agents are monitored.
Further, proposed kill-switch requirements are only one potential response tool. While shutdown mechanisms are worth considering, and potentially implementing, they alone cannot guarantee agent security. Effective oversight will need stronger controls, ongoing monitoring capabilities, and ways to consistently audit agentic activity.
Judge rules in favor of blacklisting Anthropic.
THE NEWS
On Friday, the US Court of Appeals for the District of Columbia Circuit ruled that the Trump administration acted legally and constitutionally when it labeled Anthropic a supply chain risk at the beginning of 2026. In the court’s decision, the judges found that the Pentagon had “ample support for its conclusion.”
The court also wrote that Anthropic’s First Amendment rights were not violated by the Pentagon labeling the company a risk based on the terms of a government contract and not the company's views.
Additionally, the court noted that:
“It is undisputed that Anthropic can and does control how Claude responds, or fails to respond, to user prompts.”
Judge Karen LeCraft Henderson, who was a member of the three-judge panel, did publish a dissenting opinion noting that the government interpreted the law about supply chain risks too broadly. Judge Henderson wrote:
“I cannot agree that this is the scenario the Congress had in mind.”
In response to the ruling, Anthropic stated that the company was reviewing the court’s decision and that they were “considering all options.”
THE KNOWLEDGE
The ruling creates a split with another federal case in California, where Judge Rita Lin reached a different decision. Judge Lin sided with Anthropic, finding that the government had exceeded its authority when labeling the company as a supply chain risk.
Judge Lin wrote that while the Department of War is free to select what AI vendors it wants to use, the evidence showed that the broader measures imposed on Anthropic were “illegal and baseless.” Her ruling also found that the supply-chain risk designation violated Anthropic’s First Amendment rights and that the company was denied the “pre-deprivation process” required under the Fifth Amendment.
The two cases present significantly different interpretations of the government’s authority to use the supply-chain risk designation. The conflicting rulings now leave Anthropic’s position for federal contracts subject to further legal proceedings. These cases will likely result in further appellate review, potentially giving higher courts, including the Supreme Court, the opportunity to clarify how existing supply-chain risk authorities apply to AI companies and the limits of the government’s ability to restrict their federal contracts.
The conflicting rulings leave important questions about the government’s authority over AI vendors unresolved. For government agencies and AI companies, the outcome could shape how national security concerns are balanced against the rights and policies of companies providing increasingly important AI systems.
THE IMPACT
These cases will have broader implications beyond Anthropic and the federal government. If the government has broad authority to designate AI vendors as supply-chain risks, other companies could face similar scrutiny based on concerns about how their models are developed, controlled, or deployed. Conversely, if courts place greater limits on that authority, the government may have fewer options for restricting vendors it considers security risks.
For government agencies, the dispute highlights the difficulty of balancing access to increasingly important AI capabilities with supply-chain and national security concerns. For AI companies, it also illustrates that decisions about how models are controlled and what uses they permit can have consequences beyond product policy.
As litigation continues, the key question will be where courts draw the line between security and rights.
This Week's Caveat Podcast: Anthropic’s court battles.
Dave Bittner and Ben Yelin examine two stories. First, they discuss the DC Circuit Court’s decision to uphold Anthropic’s designation as a supply-chain risk and what the ruling could mean for federal contractors. They then look at how courts are beginning to allow AI prompt logs to be used as evidence and what this could mean for AI-related investigations.
OTHER NOTEWORTHY STORIES
Anthropic says rogue AI agents pose uncertain legal risks.
What: Anthropic is concerned that it could face legal claims from customers over the actions of its rogue AI agents.
Why: On Tuesday, Anthropic detailed its concerns regarding the blowback the company expects to face for its rogue agentic activity. The company noted that:
“These autonomous capabilities could increase the potential for harm, as errors, misalignment, or security exploits may result in real-world consequences.”
The company expressed concerns that unsettled laws leave significant gaps when determining if agentic actions will trigger liability or negligence violations. These gaps could likely create impacts for developers if greater ownership or responsibility is placed on companies rather than users.
SEPTEMBER 29, 2026 | Source: Reuters
Appeals court upholds AI training lawsuit decision.
What: A US appeals court rejected Ross Intelligence’s appeal.
Why: On Tuesday, the Philadelphia- based 3rd US Circuit Court of Appeals rejected an appeal from Ross Intelligence that it made fair use of Thomson Reuters’ Westlaw platform.
While the court’s reasoning is currently sealed, the case ties back to a 2020 lawsuit. The lawsuit involved Thomson Reuters’ suing Ross Intelligence for copying the Westlaw platform’s “headnotes” and alleging that Ross was misusing thousands of headnotes to train its legal search engine.
That case was ruled on in 2025 when a federal judge found:
“Ross took the headnotes to make it easier to develop a competing legal research tool. So Ross’s use is not transformative.”
SEPTEMBER 29, 2026 | Source: Reuters
