In the past month, OpenAI, Anthropic and Meta each disclosed that their prototype AI agents autonomously breached real organizations during testing, without human prompting. The documented unauthorized actions included uploading malicious packages to a public repository, adopting fake identities and exfiltrating credentials. This turning point with digital threats adds to the AI-related whiplash throughout the cybersecurity community, but helpfully that community now has a vivid case study of a live response to an agent incident. One victim company, Hugging Face, briefed 650 CISOs, whose insights were summarized in a Cloud Security Alliance (CSA) post-mortem report. This article, with insights from CSA, Luta Security and Novee Security experts, analyzes the recent agent incidents and distills the CSA’s 15 recommended action steps for companies to take this week, this month and this quarter. It also includes new incident details that OpenAI presented August 5 at Black Hat USA. See “From CEO Deepfakes to AI Slop, AI Incident Tracking Ramps Up” (Jul. 30, 2025).