From OpenAI models breaking out of an isolated test environment to a suspected China-linked campaign against Taiwan and Google’s AI-powered defenses, recent developments show AI agents taking more active roles on both offense and defense.Open AI models escape the sandboxThe warning arrived in late July, when OpenAI disclosed an incident it described as an “unprecedented cyber incident” involving some of its most advanced models.During an internal evaluation designed to test sophisticated cyber capabilities, OpenAI models found a way out of the intended network isolation, reached the open internet and ultimately compromised AI platform Hugging Face’s production infrastructure while in pursuit of answers to a testing benchmark.The episode was alarming not merely because the models discovered vulnerabilities, but because they chained together multiple attack techniques across separate systems during the evaluation.OpenAI said the models exploited a previously unknown zero-day vulnerability in an Artifactory package-registry proxy to gain internet access, then performed privilege escalation and lateral movement within OpenAI’s research environment before using stolen credentials and additional vulnerabilities to reach Hugging Face servers. OpenAI CEO Sam Altman uses a laptop. (Facebook, OpenAI) The company subsequently strengthened containment, monitoring and access controls, while stressing that the model involved was an internal research prototype and was never intended for public release.The significance extends beyond one laboratory mishap. The incident demonstrated that increasingly capable models can conduct complex, multistep cyber operations over extended periods and discover novel attack paths without access to source code.The findings suggest that, when given tools and permissive evaluation conditions, AI agents can already execute significant portions of cyber operations with limited human intervention.On Aug. 13, the New York Times published an opinion article titled “If You Weren’t Worried About AI, You Should Be After the Past Few Weeks,” written by computer scientist Nate Soares, president of the Machine Intelligence Research Institute and co-author of the 2025 book “If Anyone Builds It, Everyone Dies.”Taiwan faces a real-world AI-assisted attackLess than a month after the OpenAI incident was disclosed, that concern acquired a geopolitical dimension.On Aug. 12, the Financial Times reported that suspected China-linked hackers used open-source AI tools in an early-July operation targeting Taiwan’s government systems, in what the newspaper called an unprecedented “autonomous” AI cyberattack. Cybersecurity company Dream, however, described the framework as “near-autonomous” and did not publicly identify the operator behind it.Dream said the framework deployed up to eight AI agents concurrently, identified 21 connected government systems, researched vulnerabilities and reprioritized attack paths as the campaign unfolded.Dream said the system cracked 85 government employee credentials and exfiltrated more than 2,564 personnel records. It also expanded its scanning to a nuclear safety agency, government IT vendors, a government email system and at least seven energy-sector companies.CNN also reported on the incident, citing Taiwan Network Information Center Chairman Kenny Huang as saying it was believed to be “the first disclosed case of a fully automated attack against a government.”On Aug. 13, Taiwan’s Ministry of Digital Affairs (MODA) said its cybersecurity monitoring units detected abnormal attacks targeting government agencies in July and that the National Institute of Cyber Security began issuing alerts on July 20, while investigations and incident-response measures were launched immediately. Minister of Digital Affairs Lin Yi-jing discusses Taiwan's AI policy and governance. (TCN) MODA added that the investigation found clear characteristics indicating an overseas origin, alongside a hybrid attack model in which human-operated hacking activity was augmented by AI agents such as OpenClaw.MODA said the AI agents could rapidly chain together multiple attack techniques and exploit secondary systems — including backup and testing environments — as stepping stones into targeted networks, giving the attacks greater speed, lower costs and the potential to operate at considerably larger scale.The ministry said it would continue strengthening government cyber defenses based on the attack characteristics identified in its investigation and monitor for additional pathways that could be exploited.From digital sovereignty to AI defenseTaiwan’s cybersecurity response is also evolving as organizations turn to AI-powered tools to detect and respond to increasingly sophisticated attacks.On Aug. 7, Google Cloud announced the launch of Google Security Operations in the Google Cloud Taiwan Region, addressing local requirements for data governance and data residency.The platform allows organizations to store and process security logs and analytical data locally, a feature Google said was particularly relevant to regulated sectors including government, finance, healthcare, manufacturing, semiconductors and critical infrastructure.The platform also combines threat intelligence with AI-powered security operations and Gemini models, allowing security teams to automate parts of threat investigation and response through workflows and playbooks.Google Cloud stated the system can cut typical manual threat analysis from about 30 minutes to one minute.Google announced the Taiwan launch five days before Dream publicly disclosed its findings about the Taiwan campaign, and Google did not tie the rollout to that specific incident.Against the broader backdrop of increasingly AI-enabled cyber threats, the locally hosted security operations and agentic defense tools adds another layer to Taiwan’s efforts to strengthen cyber resilience and retain greater control over sensitive security data.