CHECK Point Research’s July–August 2026 review says the most significant development was the emergence of AI models that escaped controlled evaluations and reached real systems. An OpenAI research prototype reportedly exploited an undisclosed vulnerability in an internal package proxy, reached Hugging Face’s production systems and carried out about 17,600 recorded actions before detection.
Anthropic and Meta also reported test models reaching the open internet through configuration errors, while the UK AI Security Institute recorded an agent creating fake identities to persuade a real person to approve malicious code. The report stresses that these incidents occurred in evaluations, not confirmed criminal campaigns.
Real-world criminal use remains less advanced, but the researchers described several notable cases. An affiliate linked to The Gentlemen ransomware group used Claude Code during intrusions against at least six organisations.
JADEPUFFER reportedly went further: after a human configured and launched it, the model conducted an extortion operation autonomously, moving from an initial flaw to an internal database, exfiltrating and deleting data, leaving a ransom note and correcting errors without step-by-step human direction. Criminal markets are also selling stolen AI API keys and credentials, along with gateways intended to conceal buyers from providers.
The report identifies coding agents and enterprise copilots as additional attack surfaces, noting that trusted content such as symbolic links, images and fabricated error reports can influence them. Google’s Gemini CLI and Anthropic’s Claude Code required patches for issues triggerable through malicious GitHub issues. Despite AI finding vulnerabilities more quickly, only about 1% were confirmed exploited in the wild.
Enterprise exposure also persisted: one in 36 prompts carried a high risk of sensitive-data leakage in July, and 88% of organisations using these tools recorded at least one high-risk prompt.