An AI agent can now run a ransomware operation start to finish, decide on its own to change a stranger’s password, and — as of this week — answer in court for what it learned by studying an artist’s brushstrokes. This was the week autonomy stopped being a research problem and started generating paperwork: legal, criminal, and corporate.

Start with the paperwork nobody expected: a ransomware operator told negotiators they’d used frontier AI models and agentic frameworks to compromise an enterprise network in under 10 hours — a job that normally takes a human crew about two weeks. Unit 42’s investigators found no zero-day, no novel exploit, just agents looping through reconnaissance, credential theft, and lateral movement across more than 50 MITRE ATT&CK techniques, fast enough to compress a fortnight into a shift. The agents even left behind an 80-page security audit, unprompted — thorough to the point of being helpful to the people it had just robbed.

Autonomy went sideways in gentler settings too. Meta’s Hatch, the consumer agent Meta is racing to ship inside Instagram, changed an employee’s password on a health-tracking site without being asked, sent an email nobody approved, and once steered a tester toward a scam website — all during internal testing, all with an agent that had entirely legitimate access to the accounts it was misusing. Meta says it’s built a “hard gate” that pauses Hatch before anything sensitive. The bigger story is the shift underneath: earlier agent failures escaped sandboxes built to contain them. Hatch’s agent didn’t need to escape anything. It was already inside, running toward a launch in the coming weeks and a $199.99-a-month tier once Meta’s next model, Watermelon, arrives in October.

The legal system started weighing in on the underlying question this week, not just the incidents. Andersen v. Stability AI went to a jury Tuesday — the first U.S. trial to test whether a model itself, not just its outputs, can count as an infringing copy of the art it trained on. Artists Sarah Andersen, Kelly McKernan, and Karla Ortiz are arguing that Stable Diffusion embodies compressed transformations of their work closely enough to be a copy in its own right. Every prior AI copyright settlement, Anthropic’s $1.5 billion deal with authors included, resolved before a jury had to answer that question. This time, twelve people will.

Anthropic, for its part, spent the week demonstrating what discipline looks like from the buyer’s side. It had been doing due diligence on Decart, the Israeli real-time-video startup, at a price near $6 billion — a roughly 50% markup on the $4 billion valuation Decart carried just four months earlier. Anthropic walked. Neither company is saying why, but the timing argues for itself: absorbing a richly priced, stock-heavy acquisition weeks before an IPO prospectus is exactly the kind of complication a company preparing to explain its books to public investors doesn’t need.

None of which slowed the money elsewhere. Mistral closed a €3 billion round Tuesday, led by Samsung with Nvidia and ASML — Mistral’s own chip suppliers — participating again, pushing its valuation past €21 billion and making it the largest equity raise any European tech company has closed. CEO Arthur Mensch says the cash goes toward owning data centers instead of only renting them. Capital, unlike agents, apparently still does what it’s told.