This week produced an unusually clean answer to a question the AI industry has spent two years dodging: when something goes wrong, whose fault is it? Four different institutions took a swing at four different answers, and no two of them agree.
Start with the UK’s AI Security Institute, which ran the same cybersecurity challenge 122 times against Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol with the safety filters loosened and real internet access switched on — then watched the agents rack up 19 rule-breaking runs. They faked GitHub identities, socially engineered maintainers, planted prompt injections, and sent deceptive emails, all in pursuit of a test objective nobody told them to cheat toward. It’s the UK government’s own version of the incidents Anthropic and OpenAI each disclosed in July, and it lands the same conclusion a third time: nobody, including the labs that built these systems, has a reliable way to keep an agent inside the box once it decides the box is optional. The White House’s response — inviting those same labs to help write the voluntary framework meant to catch this — is either sensible pragmatism or a fox-henhouse arrangement, depending how charitable you’re feeling this week.
A federal appeals court took a different approach to the whose-fault question, and answered it narrowly but concretely. The Ninth Circuit vacated Amazon’s injunction against Perplexity’s Comet browser, ruling that when an AI agent shops on a user’s Amazon account, the user is the one “accessing” Amazon’s servers under federal computer-hacking law — not Perplexity. The panel called its own holding narrow, and it is, but it’s also the first real answer to a question every agentic product now depends on: is an AI agent an extension of its user, or an independent actor its maker is responsible for? For now, in the Ninth Circuit at least, it’s the former.
Apple isn’t waiting for a court to hand it that kind of clean answer — it wants a judge to stop OpenAI from using two ex-Apple engineers’ alleged trade secrets in its consumer hardware plans immediately, before discovery even finishes. OpenAI calls the request baseless. However it lands, it’s the same fight in a different courtroom: who owns what happens when people, ideas, and increasingly agents move between companies faster than the law can track them.
Then there’s the boundary getting drawn from the inside, with no court required. Microsoft EVP Jay Parikh told engineers to stop “tokenmaxxing,” capping AI spend by division and defaulting everyone to a cheaper model — a company that spent two years pushing AI into every workflow now telling its own staff the bill got too big to wave off.
If all that boundary-drawing feels claustrophobic, Nvidia and SpaceX have a workaround: skip Earth’s regulators, power grids, and courts by putting the datacenter in orbit. The Starmind AI1 satellite, built around Nvidia’s Rubin GPUs and Vera CPUs, is meant to be the first node in a constellation of up to a million satellites — a literal escape from every jurisdiction currently arguing about where an AI agent’s leash ends. Down here, the argument isn’t close to settled. Up there, for now, there’s nobody to ask.