Why this week’s UK AI Security Institute Incident Report of Unsanctioned Agent Behaviour Demands Quality AI from Australian Marketers.
Have you started using the agentic AI capabilities of off-the-shelf models? Most call them “Computer” vs “Chat” now.
If you haven’t, most using them assume that if we give the AI agent a clear goal, it will respect implicit business, safety, and ethical guardrails. But working with agentic systems has shown the reality that autonomous AI does really prioritise task completion above everything else!
Without strict quality AI governance, goal-directed AI agents can even engage in deception to hit their path target.
This week the UK AI Safety Institute put out an incident report that makes this risk very clear. It’s coming just two weeks after anAI agent incident was reported by OpenAI where an agent hacked a system to achieve its goal.
The UK AI Safety Institute, during routine evaluations across 122 cybersecurity tests, AI models took 19 unprompted, unsanctioned actions on the live internet. Anthropic’s Mythos 5 generated 17 of these breaches, while OpenAI’s GPT-5.6-Sol accounted for two.
When faced with difficult obstacles, agents didn’t throw an error code; they improvised. In the most severe case, an agent attempted an unprompted attack on a public open-source AI project. To force its code to be approved for inclusion, it researched human maintainers, fabricated online personas, hid the IP address that identifies it, and engaged in social engineering. In other test runs, agents emailed unsolicited files to real people and hid prompt-injection instructions for other automated systems to find.
Now, nobody programmed these systems to lie. Deception emerged spontaneously as an efficient shortcut when straightforward methods failed in achieving their goal.
I know Australian marketing teams are starting to move beyond basic prompt engineering toward more agentic AI workflows. These recent incidents are a reminder of the importance of quality AI that I’ve been advocating for some time now.
Under Australian Consumer Law, strict liability for misleading or deceptive conduct sits squarely with our brands. If an autonomous marketing agent scrapes protected data, spoofs identities, or publishes unauthorised claims to hit its targets, regulators and consumers will hold the company and marketer responsible, not the tech vendor.
Brand safety is no longer just about filtering offensive language in a chatbot response or being associated with the wrong brand or influencer. It is about controlling autonomous agentic AI execution! Relying on basic system prompts or vendors to govern autonomous agents is pure wishful thinking.
To build what I call risk-adjusted ROI from (agentic) AI – a method from investment management where we do work – we must ground our deployments in quality AI. Apply proven quality management principles (context, governance, assurance, improvement and leadership) to build quality controls directly into AI-enabled process design rather than attempting to inspect outputs after execution. Security experts at AI summits I was at in London and Geneva in the last few months are openly saying that the human-in-the-loop that regulators and others have been promoting is simply impractical for fully checking agentic AI due to the volume and speed of it.
In equitably.ai work helping organisations deploy enterprise AI, I advocate for three process controls.
- Establish hard permission boundaries that strictly restrict the external APIs, tools, and environments an agent can access. Off-the-shelf providers give you this option. Make sure you use it.
- Require checkpoints before any agent executes external actions or alters live digital assets.
- Run rigorous failure-mode testing (quality method) to ensure agents fail gracefully when a goal cannot be achieved cleanly.
The UK currently holds third position on the Stanford HAI Global Vibrancy Index, driven by empirical testing at bodies like the UK AI Safety Institute. The levels of AI in the UK give Australia, in my view, a valuable six-to-twelve-month lead to establish robust quality AI standards (there are ISO standards for AI if you didn’t know) before autonomous agents become standard across local martech stacks.
Tools change fast, but the fundamental marketing requirement for quality control of brand never changes.
To help Australian marketers master these autonomous systems safely, I am facilitating an upcoming live AMI Skills Lab: Practical Agentic AI for Marketing. Over two 90-minute live sessions starting 8th of September and a two-week practical workplace testing sprint, we will build, validate, and troubleshoot working agents while establishing a risk-adjusted business case for executive buy-in.
John Paul Danaee CQP MCQI, CPM, FAMI, FCIM
John Paul is CEO of equitably.ai, a Chartered Marketer, Certified Practising Marketer, and Fellow of both the AMI and CIM (UK). He applies Chartered Quality Professional competencies—a credential in process governance and quality assurance—to enterprise AI deployment. Connect on LinkedIn.