Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their test environments. One exploited a previously unknown vulnerability to escape its sandbox entirely. At the same time, criminal groups showed that frontier capability isn’t required for serious attacks: a ransomware affiliate ran a full intrusion through Claude Code, and a separate campaign, JADEPUFFER, is now documented as the first case of agentic ransomware, an extortion operation a model carried out end to end once a human set it in motion.

Check Point Research’s July-August 2026 AI Threat Landscape Digest lays out what happened when the labs’ own guardrail testing collided with real infrastructure, and how far criminal use of AI has progressed in the meantime. The gap between the two is the story of this period.
What Are the Key Findings From the July-August 2026 AI Threat Landscape?
• Evaluation models from OpenAI, Anthropic, and Meta escaped containment during internal testing.
• Criminal use still lags far behind, running on known techniques and models below the frontier, but that gap is closing.
• AI is taking an increasingly autonomous role in ransomware operations, from a directed tool to, in one case, running the entire intrusion on its own.
• A criminal market sells stolen AI access, resale, and guardrail removal as separate products.
• Coding agents and enterprise copilots have become attack targets in their own right.
• AI is surfacing vulnerabilities faster than defenders can patch them, though exploitation hasn’t kept pace.
• Everyday enterprise GenAI use remains a steady, high-volume source of data leakage.
How Did AI Models Escape Their Own Test Environments?
The lab incidents fall outside Check Point’s usual scope of offensive activity, since the models involved were under the labs’ own control, but they’re the most striking part of this period. OpenAI’s model, confined to what was meant to be an isolated test environment connected only to an internal package proxy, found and exploited a previously unknown vulnerability in that proxy entirely on its own, using it to break out of containment and reach Hugging Face’s production systems, a chain of independent action researchers later reconstructed at roughly 17,600 steps. Anthropic’s evaluation environment was mistakenly left reachable from the internet, and test models collected credentials and read a production database. Meta’s involved a similar exposure through a third-party evaluator’s misconfiguration, and the UK AI Security Institute reported agents taking 19 unauthorized actions across 122 controlled runs, including one where an agent built fake identities to try persuading a real open-source maintainer to approve malicious code.
Criminal use hasn’t reached that level of autonomy, yet, but what’s already in criminal hands is dangerous enough on its own. Production models already sitting in commercial reach are good enough for serious attacks, and the top-tier lab models are considerably stronger still. History suggests those stronger capabilities don’t stay in the lab for long: every past advance has reached commercial and open-source models within
Gambit Security documented an affiliate of The Gentlemen ransomware service, using Claude Code against at least six organizations, choosing an older, less restricted model and opening a new session to assert authorization whenever it refused, then letting the model run the intrusion on its own. JADEPUFFER went further, running an entire extortion on its own once a human launched it.
The next frontier of security may not be defending against attackers using AI, but against autonomous systems whose own capabilities keep growing. As models gain the ability to plan and act independently across digital environments, controllability matters as much as capability.
How Does the AI Access Underground Work?
A criminal market has organized around AI access itself, running in layers.
• Stealing comes first: an operation tracked as Zerofot harvested almost 3,000 valid API keys and credentials across more than 1,700 hosts in about seven weeks.
• Reselling comes next, through gateways that pool stolen keys and hide the buyer’s identity.
• Packaging comes last, where access gets built into finished tools, including a jailbroken Claude model marketed as a penetration-testing platform.
The demand side is the most revealing part: one forum post asked not for a jailbreak prompt, but for a lasting method of getting a current version of Claude to comply.