In tests and a small number of documented cases, autonomous AI agents have carried out activities including reconnaissance, production database deletion, and corporate data exfiltration. These incidents involve named enterprises, assigned CVEs, and one formal legal ruling with financial damages. Across these cases, AI systems or agents used legitimate access, manipulated workflows, or control gaps …