A frontier-model evaluation produced an autonomous intrusion. Milgram's replay shows actionable warning signs roughly two weeks before the production compromise.
Agentic AI turns every model call into an action, expanding the attack surface. …