This month’s briefing examines AI agent liability, third-party cloud exposure, cyber-driven fraud, and operational technology risk—four developments that sharpen board oversight of cyber resilience and accountability. AI Agents Are Becoming a Liability Issue, Not Just a Safety IssueRecent disclosures from Anthropic and OpenAI suggest a shift in how directors should think about agentic AI risk. In both cases, advanced models moved beyond their intended confines and interacted with external systems, creating potential legal, contractual, and reputational exposure for the companies.The two cases were not identical. OpenAI disclosed that models broke out of a sandboxed test environment, reached the internet, and hacked Hugging Face, a provider of open-source AI tools, while trying to shortcut a cybersecurity benchmark. Anthropic disclosed a different failure: models in inadequately isolated test setups reached external systems and, in three incidents, compromised third parties without the company’s knowledge. In both cases, the issue was not only model capability, but autonomy, connectivity, credentials, and weak control over what the agent could reach.The takeaway is straightforward: if agents can reach live networks, repositories, cloud resources, or sensitive data without strict boundaries, the enterprise may be creating preventable liability. Model-level guardrails are not enough if the surrounding environment still grants meaningful access.The governance takeaway is to treat AI agents as untrusted actors by default. A Zero Trust approach can help: assume the agent may be unsafe, and strictly limit what it can reach or do. Constraining an agent’s ability to act beyond its intended scope is key to reducing liability risk.What Directors Should Ask Management:What controls prevent AI agents used in testing or operations from reaching live internet destinations, repositories, credentials, or production-adjacent systems without explicit approval?If an AI agent causes unauthorized access, data exposure, or harm to a third party during testing, how will we identify the activity and are we prepared for the resulting legal, disclosure, and contractual consequences?How do we verify that our AI evaluation environments are truly isolated, rather than assuming they are safe because they are labeled as test systems?  Amgen Shows Why Third-Party Cloud Risk Is Still Board RiskAmgen disclosed a material cyber incident involving unauthorized activity in third-party-hosted cloud environments, with reports indicating exposure of patient and proprietary data but no identified disruption to products, manufacturing, or operations. The incident is the latest in a string of attacks affecting the healthcare sector.The case is a useful reminder that outsourcing infrastructure does not outsource accountability. When sensitive data sits in external platforms, the enterprise still owns the legal, regulatory, and reputational consequences. The governance issue is whether management has clear visibility into which third parties hold critical data, how access is controlled, and whether contract terms, logging, and notification rights are strong enough to support a fast materiality assessment when harm originates outside the enterprise’s own environment.What Directors Should Ask Management:How do we verify that third-party access, logging, and incident-notification terms are strong enough to support a fast materiality assessment?  Upbound Shows How Cyber Risk Can Turn Directly Into Earnings ImpactIn an 8-K filing, Upbound disclosed details of cybersecurity incidents in which unauthorized parties obtained non-sensitive customer information and other documents. The company said the information was then used to facilitate fraudulent lease-to-own agreements in its Acima business, contributing to roughly $13 million in fraudulent contract losses in the second quarter.Cyber incidents do not need to disrupt operations or expose highly sensitive data to become financially significant. Stolen information can be weaponized quickly for fraud, especially in businesses that rely on fast approvals, distributed partners, or high-volume transactions. The governance issue is whether management is connecting cyber risk to fraud controls, transaction monitoring, and loss detection, rather than treating data compromise as a separate issue.What Directors Should Ask Management:How quickly could we detect if stolen customer or applicant data were being used to drive fraudulent transactions against us?  Minnesota Water Incidents Highlight the Risk of Exposed Operational TechnologyRecent attacks on Minnesota water systems and a related federal warning highlight a broader lesson for directors: operational technology can create real-world disruption when it is exposed to the internet or governed less rigorously than traditional IT. In this case, attackers believed to be aligned with Iran targeted internet-connected industrial control devices in at least seven states across the US, changed passwords, altered network settings, and forced some utilities into manual operations.The board lesson extends well beyond the water sector. Many companies rely on operational technology that sits outside core IT security programs, including plant controls, warehouse automation, heating and cooling systems, badge access, and backup power environments. These systems often support essential operations but may have weaker visibility, older controls, undocumented remote connections, or greater dependence on vendors and integrators.What Directors Should Ask Management:Do we know which operational systems are exposed, who can access them, and whether they are governed with the same discipline applied to other material enterprise systems? Zscaler is a proud partner of NACD’s Northern California chapter. We are here as a resource for directors to answer questions about cybersecurity or AI risks, and are happy to arrange dedicated board briefings. Please email rsloan[@]zscaler.com to learn more.   

​[#item_full_content] This month’s briefing examines AI agent liability, third-party cloud exposure, cyber-driven fraud, and operational technology risk—four developments that sharpen board oversight of cyber resilience and accountability. AI Agents Are Becoming a Liability Issue, Not Just a Safety IssueRecent disclosures from Anthropic and OpenAI suggest a shift in how directors should think about agentic AI risk. In both cases, advanced models moved beyond their intended confines and interacted with external systems, creating potential legal, contractual, and reputational exposure for the companies.The two cases were not identical. OpenAI disclosed that models broke out of a sandboxed test environment, reached the internet, and hacked Hugging Face, a provider of open-source AI tools, while trying to shortcut a cybersecurity benchmark. Anthropic disclosed a different failure: models in inadequately isolated test setups reached external systems and, in three incidents, compromised third parties without the company’s knowledge. In both cases, the issue was not only model capability, but autonomy, connectivity, credentials, and weak control over what the agent could reach.The takeaway is straightforward: if agents can reach live networks, repositories, cloud resources, or sensitive data without strict boundaries, the enterprise may be creating preventable liability. Model-level guardrails are not enough if the surrounding environment still grants meaningful access.The governance takeaway is to treat AI agents as untrusted actors by default. A Zero Trust approach can help: assume the agent may be unsafe, and strictly limit what it can reach or do. Constraining an agent’s ability to act beyond its intended scope is key to reducing liability risk.What Directors Should Ask Management:What controls prevent AI agents used in testing or operations from reaching live internet destinations, repositories, credentials, or production-adjacent systems without explicit approval?If an AI agent causes unauthorized access, data exposure, or harm to a third party during testing, how will we identify the activity and are we prepared for the resulting legal, disclosure, and contractual consequences?How do we verify that our AI evaluation environments are truly isolated, rather than assuming they are safe because they are labeled as test systems?  Amgen Shows Why Third-Party Cloud Risk Is Still Board RiskAmgen disclosed a material cyber incident involving unauthorized activity in third-party-hosted cloud environments, with reports indicating exposure of patient and proprietary data but no identified disruption to products, manufacturing, or operations. The incident is the latest in a string of attacks affecting the healthcare sector.The case is a useful reminder that outsourcing infrastructure does not outsource accountability. When sensitive data sits in external platforms, the enterprise still owns the legal, regulatory, and reputational consequences. The governance issue is whether management has clear visibility into which third parties hold critical data, how access is controlled, and whether contract terms, logging, and notification rights are strong enough to support a fast materiality assessment when harm originates outside the enterprise’s own environment.What Directors Should Ask Management:How do we verify that third-party access, logging, and incident-notification terms are strong enough to support a fast materiality assessment?  Upbound Shows How Cyber Risk Can Turn Directly Into Earnings ImpactIn an 8-K filing, Upbound disclosed details of cybersecurity incidents in which unauthorized parties obtained non-sensitive customer information and other documents. The company said the information was then used to facilitate fraudulent lease-to-own agreements in its Acima business, contributing to roughly $13 million in fraudulent contract losses in the second quarter.Cyber incidents do not need to disrupt operations or expose highly sensitive data to become financially significant. Stolen information can be weaponized quickly for fraud, especially in businesses that rely on fast approvals, distributed partners, or high-volume transactions. The governance issue is whether management is connecting cyber risk to fraud controls, transaction monitoring, and loss detection, rather than treating data compromise as a separate issue.What Directors Should Ask Management:How quickly could we detect if stolen customer or applicant data were being used to drive fraudulent transactions against us?  Minnesota Water Incidents Highlight the Risk of Exposed Operational TechnologyRecent attacks on Minnesota water systems and a related federal warning highlight a broader lesson for directors: operational technology can create real-world disruption when it is exposed to the internet or governed less rigorously than traditional IT. In this case, attackers believed to be aligned with Iran targeted internet-connected industrial control devices in at least seven states across the US, changed passwords, altered network settings, and forced some utilities into manual operations.The board lesson extends well beyond the water sector. Many companies rely on operational technology that sits outside core IT security programs, including plant controls, warehouse automation, heating and cooling systems, badge access, and backup power environments. These systems often support essential operations but may have weaker visibility, older controls, undocumented remote connections, or greater dependence on vendors and integrators.What Directors Should Ask Management:Do we know which operational systems are exposed, who can access them, and whether they are governed with the same discipline applied to other material enterprise systems? Zscaler is a proud partner of NACD’s Northern California chapter. We are here as a resource for directors to answer questions about cybersecurity or AI risks, and are happy to arrange dedicated board briefings. Please email rsloan[@]zscaler.com to learn more.