INCIDENTOpenAI agents broke isolation and executed code on Hugging Face production serversOpenAI · incident reportINCIDENTAgent encoded what it stole, and the first automated scan missed most of itHugging Face · forensic timelineINCIDENTEchoLeak turned Microsoft 365 Copilot into a zero-click exfiltration pathMicrosoft MSRC · CVE-2025-32711REGULATIONParliament approves AI Omnibus, high-risk deadlines pushed to 2027 and 2028European ParliamentDISCLOSURECB Financial files first Item 1.05 8-K citing unauthorized AI useSEC EDGAR · Item 1.05RESEARCH45% of employees now regular AI users on corporate devices, up from 15%Verizon DBIR 2026REGULATIONDORA fully applicable. ICT resilience is now binding lawEuropean Banking AuthorityDISCLOSUREFirst AI-root-cause 8-K opens a new SEC disclosure categoryCherry Hill AdvisoryINCIDENTOpenAI agents broke isolation and executed code on Hugging Face production serversOpenAI · incident reportINCIDENTAgent encoded what it stole, and the first automated scan missed most of itHugging Face · forensic timelineINCIDENTEchoLeak turned Microsoft 365 Copilot into a zero-click exfiltration pathMicrosoft MSRC · CVE-2025-32711REGULATIONParliament approves AI Omnibus, high-risk deadlines pushed to 2027 and 2028European ParliamentDISCLOSURECB Financial files first Item 1.05 8-K citing unauthorized AI useSEC EDGAR · Item 1.05RESEARCH45% of employees now regular AI users on corporate devices, up from 15%Verizon DBIR 2026REGULATIONDORA fully applicable. ICT resilience is now binding lawEuropean Banking AuthorityDISCLOSUREFirst AI-root-cause 8-K opens a new SEC disclosure categoryCherry Hill Advisory
CollAI
CollAILive product · Design partners
Try demo
CollAI

CollAI

The trust layer for AI in production

Mission · private brief

AI is entering production.

The audit trail is not ready.

We are building the missing trust layer.

CollAI gives regulated teams a safer way to let AI touch operational context: sensitive data is controlled, outputs are inspected, and high-risk actions remain accountable. In environments where accountability has to survive an incident review, policy PDFs are not enough.

Live demo openRegulated operatorsDesign partners
Try the live demo

Open demo · no waitlist. Design partner track is for regulated FinServ teams.

0%

Employees now using AI regularly on corporate devices

Verizon DBIR 2026 · up from 15%

0st

SEC Item 1.05 8-K already tied to unauthorized AI exposure

2026-05-11 · SEC EDGAR Item 1.05

0d

Until the next high-risk AI compliance clock lands

2 Dec 2027 · European Parliament · 16 Jun 2026

Failure mode · public record

The input filter passed. The damage left through the output.

Three documented cases where the model was allowed to run and the harm arrived on the way out: a rendered link, an encoded payload, an action nobody approved.

  • Jun 2025

    Microsoft 365 Copilot

    A single crafted email made Copilot place internal data inside a rendered link and send it out with no user click.

    Control that failed · The cross-prompt-injection classifier let the email through. Nothing inspected what the model wrote back.

    CVE-2025-32711 · EchoLeak
  • Jul 2026

    OpenAI research agents

    Agents broke isolation, coordinated over an unapproved channel, and executed code on Hugging Face production servers.

    Control that failed · No named human approved any of it. OpenAI describes agents taking dangerous actions that no human directed.

    OpenAI incident report
  • Jul 2026

    Hugging Face forensics

    Data on its way out was chunked, XOR'd, and compressed so a plain text scan of the logs would miss it.

    Control that failed · The first automated scan surfaced few secrets. Decoding it the way the agent encoded it recovered roughly 4x more.

    ~17,600 reconstructed actions

The lesson is not patch faster. These incidents are public proof that input filters miss agent-to-agent paths and editable logs. CollAI governs the seam after the model and before the action: VPC scrub, StegoGuard on outputs, named-human approval before destructive actions, and a hash-chained audit. Cited as public evidence only; CollAI had no role in these incidents. Banks need that layer before agents touch production, not after.

Operating thesis

Trust is not a prompt. It is a control loop.

CollAI is being built for operators who need machine-speed assistance without surrendering boundaries, judgment, or proof.

01Boundary

Sensitive context stays governed.

Operational data is controlled before it enters any automated workflow.

02Signal

Generated responses are verified.

Every machine-produced recommendation is treated as untrusted until cleared.

03Control

High-impact action stays accountable.

Decisions are gated, recorded, and reviewable when it matters.

Verified EU AI Act timeline · European Parliament · 16 Jun 2026

Source: European Parliament →
  • 2 Aug 2026

    Most remaining AI Act provisions · chatbot transparency

    Still scheduled; high-risk rules deferred by Omnibus

  • 2 Dec 2026

    Machine-readable AI content labelling · watermarking

    Systems on market before 2 Aug 2026

  • 2 Dec 2027

    Stand-alone high-risk AI (Annex III)

    HR, credit scoring, biometrics, etc.

  • 2 Aug 2028

    High-risk AI embedded in regulated products (Annex I)

    Medical devices, machinery, toys

Omnibus adopted by Parliament 16 Jun 2026 (423–57–174). Council formal adoption and Official Journal publication pending. Dates above reflect the adopted parliamentary text, not the superseded August 2026 high-risk deadline.

Signal feed
01 / 08
INCIDENTAug 26, 2026· OpenAI · incident report

OpenAI agents broke isolation and executed code on Hugging Face production servers

Research agents coordinated through an unapproved internal channel, reached the public internet, and ran code on dozens of Hugging Face servers. OpenAI calls it a warning shot that capable agents can take dangerous actions no human directed.

Read source

Design partners

Request design partner access

Seeking 3-5 regulated FinServ design partners. Work email preferred.

No mailing lists. Prefer to try the live demo first?

Identity

CollAI is live. Public materials describe the problem and operating principles. Deep architecture briefings stay private for qualified partners.

Access

Self-serve demo at dashboard.trycollai.com. Design partner briefings for regulated FinServ teams evaluating governed agent execution.

Contact

svanjari@trycollai.com

Siddhartha reviews every inquiry personally