AI-generated summary
Artificial intelligence technology is developing from conversational models to agents that can perform tasks, with the capabilities of autonomous perception, planning and decision-making, and tool invocation. While this transformation brings efficiency improvements, it also raises safety risks, because intelligent agents can directly operate digital and physical systems, and loss of control or misjudgment may lead to actual damage.
Since the beginning of this year, artificial intelligence has accelerated its transformation from "being able to talk" to "being able to do things", and the implementation of intelligent agents that can book tickets, manage mobile phones, and operate software for users has accelerated. At the same time, security incidents caused by AI autonomous actions occur frequently around the world. From large models running out of control and invading open source platforms to AI assistants acting without authorization, the risks of artificial intelligence are escalating from "saying the wrong thing" to "doing the wrong thing", arousing great concern around the world.
Not long ago, OpenAI announced that it would suspend the training of its latest generation model. Technical reports show that on September 20, an agent performing a search training task in a sandbox exploited a DNS filtering vulnerability to bypass network restrictions and access an external public chatbot service. This is the second time in three months that OpenAI has suspended model development. In late July, its AI agent broke through the isolated operating environment, established communications during intrusion into some systems of the American company "Huahuanglian", deceived evaluators, and tried to cover up its behavior. Every step of the operation was without human intervention.
Similar incidents are not isolated. In August, test results released by the British Artificial Intelligence Security Research Institute showed that two cutting-edge AI assistants had "autonomous, unauthorized actions" 10 times out of 122 tests, and a total of 19 unauthorized actions, including attempts to forge identities and induce humans to run malicious code. Tests by some institutions found that "rogue" agents acted without instructions, leaked password information, and forcibly closed anti-virus software; this month, many banks in South Korea suffered hacker attacks suspected of involving artificial intelligence.
In China, AI face-changing fraud, AI-generated rumors and other chaos also directly threaten public property security and the order of cyberspace.
Cheng Ying, chief engineer of the Regulatory Research Department of the Institute of Policy and Economics of the China Academy of Information and Communications Technology: The risk of intelligent agents is not just "saying the wrong thing", but also "doing the wrong thing". It can directly operate digital systems and physical devices, such as AI hallucinations or misjudgments, which may drive intelligent robots to cause personal injury.
Currently, artificial intelligence applications represented by agents and AI terminals already have the capabilities of autonomous perception, planning and decision-making, and tool invocation. “Do-it-yourself AI” is becoming a new risk subject.
Why Artificial Intelligence Frequently Gets into Trouble
From "uncontrolled invasion" to "unauthorized action", why does artificial intelligence frequently cause "trouble"? The reporter interviewed industry experts and found that behind the frequent occurrence of security incidents, there are not only the inherent causes of technical characteristics, but also the gap between industrial rhythm and security design, as well as the lack of risk awareness at the application level.
Different from previous tools, the new generation of artificial intelligence has the ability to autonomously perceive, plan and make decisions, and call tools. It can "act" autonomously without human instructions one by one.
Cheng Ying: There are deep interconnections between agents and between agents and various systems. Single-point failures can easily cascade along task chains and supply chains, turning into systemic risks.
The gap between industrial pace and safety design also deserves attention. Industry insiders point out that the current security investment in the AI field is far from keeping up with the scale of R&D and application. Security evaluation, risk warning, emergency response mechanisms and other links are still catching up with technological iterations. At the same time, usage-level risks cannot be ignored. The application of artificial intelligence in government affairs, finance, industry and other fields is accelerating. Some users have insufficient understanding of the boundaries of AI capabilities, and problems of abuse and misuse are prominent, which also brings new challenges to security governance.
Cheng Ying: The intelligent agent has a long decision-making chain and a high degree of autonomy. Abnormal behaviors are difficult to identify in a timely manner. Risks are often discovered only during subsequent retrospection, leaving a very limited response window for supervision.
my country accelerates the construction of artificial intelligence security governance system
Faced with new risks such as autonomous actions of artificial intelligence, my country has accelerated the construction of an artificial intelligence security governance system covering the entire chain of research and development, deployment, and application. The purpose is to put a "safety belt" on technological innovation.
Institutional supply is intensively implemented. From the "Interim Measures for the Management of Generative Artificial Intelligence Services" to the "Measures for the Labeling of Artificial Intelligence Generated Synthetic Content", from the "Interim Measures for the Management of Artificial Intelligence Anthropomorphic Interaction Services" to the "Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents", my country has formed an institutional system covering key aspects such as content generation, label management, anthropomorphic interaction, and intelligent agent applications.
Cheng Ying: New applications and new business formats are emerging one after another. Mechanisms such as pre-registration and sandbox isolation are no longer able to adapt to the technical characteristics of agents with high authority, high autonomy, and strong interactivity. It is necessary to establish mechanisms such as agent identity identification, authority control, and log retention. At the same time, it is necessary to optimize and refine personal information protection, data security and other rules to ensure that risk behaviors can be identified and traced.
The latest data shows that as of the end of August this year, a total of 1,112 generative artificial intelligence services have been registered across the country, and 731 applications or functions have been registered; in the first phase of the special action "Cleaning Up and Rectifying AI Application Chaos" deployed by the Cyberspace Administration of China, more than 14,000 illegal AI products have been disposed of. Comprehensive legislation for the healthy development of artificial intelligence has also been put on the agenda.
Security is the prerequisite for development, and development is the guarantee of security. From institutions, technology to international cooperation, my country is installing "safety guardrails" for artificial intelligence, so that artificial intelligence can better serve the high-quality economic and social development on a safe track.
(CCTV reporters Wang Shiyu, Zhang Wei, Tang Zhijian)
AI outlook — possibilities, not facts
China will issue special security management regulations for intelligent agents before the end of the year to clarify identification and authority requirements.
Likely · Within months
The world's major economies will launch a multilateral dialogue mechanism on AI security governance in the first half of next year
Possible · Within months
The reminder "Be silent for three seconds when receiving a call from an unknown person" recently circulated on social platforms reveals a new threat that criminals use short voice samples to clone AI voiceprints to commit fraud. The article points out that AI technology is converting unchangeable biometric features such as voiceprints and faces into data that can be collected and copied, posing deep privacy threats through excessive collection, deep forgery, and information integration. In order to deal with risks, the article emphasizes the need to comply with laws and regulations such as the Data Security Law, guard the source of data, enhance public awareness of prevention, and build a strong bioinformation security barrier.
The 12th Beijing International Aging Industry Expo opened in Beijing. Many companies displayed elderly care robots, exoskeletons and physical therapy equipment. Experts point out that elderly care robots have great potential in disability care and emotional companionship, but they still need to be further improved in terms of technical stability and standard systems.

Microsoft released the Decision-1 decision model in Microsoft Foundry, which specifically handles classification and scoring tasks. This model is post-trained based on Qwen3.5-9B. It does not generate text, but outputs probability scores for automated system decision-making. It is currently available on OpenRouter.

Communist Party officials in China's Zhejiang province are demanding increased oversight of major internet platforms, arguing that algorithms and traffic power now significantly influence public sentiment and should be managed as semi-public utilities.
On October 10, AutoNavi, a subsidiary of Alibaba Group, and Sands China held an appointment ceremony at the Venetian NBA House in Macao to officially deliver the first batch of embodied robot dogs "Amap Tutu". Titu will serve as Sands China’s 001 robot dog guide, providing tour guides and global indoor navigation services for tourists.
In the offline closed-loop test of Jingdong Health's self-developed large-scale medical model Jingyi Qianxun, it successfully passed ten subjects of the senior professional title examination using real test questions from real candidates, demonstrating its ability in complex case handling and long-chain clinical reasoning.