so apparently an agent was left running against a company’s systems and it just kept going, quietly poking around, for almost a week before OpenAI even clocked it.
what gets me isn’t the hack itself, it’s the timeline. we talk so much about agent capability and basically nothing about who’s watching the agent while it works unsupervised for days. I’ve had prototypes run wild on toy tasks and even then I’m checking logs every hour out of paranoia. a week of silence on something with real access is a different universe.
anyone here actually running long-lived autonomous agents in prod, what does your monitoring setup even look like for this?