AI Against Humanity
← Back to articles
Safety πŸ“… August 27, 2026

Businesses face major risks from unverified AI actions

AI agents are exposing corporate networks to serious security risks by executing unowned code. This highlights vulnerabilities in the trust model for AI usage.

Recent research has revealed significant security vulnerabilities in corporate networks due to AI agents like Claude, Codex, and Hermes automatically installing dangerous unowned code. An investigation by a stealth startup in Israel examined over 6,200 websites, including those of Fortune 500 companies, uncovering misconfigured machine-readable files (llms.txt and llms-full.txt) that inadvertently led to the execution of malicious code. Researchers registered unclaimed domain names and found that several corporate systems executed unverified commands, highlighting a broken trust model where AI relies on vendor documentation without validating its authenticity. This situation is exacerbated by the inability of AI to distinguish between trusted and untrusted instructions, as demonstrated in the Clerk case, where a legitimate command resulted in malware installation. The implications extend beyond individual companies, posing risks to entire industries and eroding trust in AI technologies. As AI becomes more integrated into business processes, the lack of transparency and accountability necessitates urgent attention to establish safeguards against these vulnerabilities, emphasizing the need for stricter oversight and governance.

Why This Matters

This article highlights the critical risks posed by AI agents that execute unverified code, potentially leading to serious security breaches in corporate environments. Understanding these vulnerabilities is essential as AI becomes increasingly integrated into various layers of technology, impacting businesses and their cybersecurity frameworks. The findings stress the urgent need for better regulatory measures and security protocols to safeguard against automatic code execution by AI.

Original Source

Claude, Codex, and Hermes installed unowned code inside corporate networks

Read the original source at arstechnica.com β†—

Type of Company

Topic