Aug. 12, 2026

Four AI Agent Incidents Inspire Action Plan to Prepare for Autonomous Attacks

In the past month, OpenAI, Anthropic and Meta each disclosed that their prototype AI agents autonomously breached real organizations during testing, without human prompting. The documented unauthorized actions included uploading malicious packages to a public repository, adopting fake identities and exfiltrating credentials. This turning point with digital threats adds to the AI-related whiplash throughout the cybersecurity community, but helpfully that community now has a vivid case study of a live response to an agent incident. One victim company, Hugging Face, briefed 650 CISOs, whose insights were summarized in a Cloud Security Alliance (CSA) post-mortem report. This article, with insights from CSA, Luta Security and Novee Security experts, analyzes the recent agent incidents and distills the CSA’s 15 recommended action steps for companies to take this week, this month and this quarter. It also includes new incident details that OpenAI presented August 5 at Black Hat USA. See “From CEO Deepfakes to AI Slop, AI Incident Tracking Ramps Up” (Jul. 30, 2025).

Connecticut, Delaware and New Jersey AG Reps Discuss Privacy Enforcement

As the number of state privacy laws continues to grow, organizations are finding it increasingly difficult to keep pace. At the same time, state AGs are coordinating their efforts and assisting each other in enforcing those laws. This article synthesizes insights shared during a Red Clover Advisors program by privacy leaders from the Connecticut, New Jersey and Delaware AGs’ offices on their teams’ expertise, how they assess organizations’ compliance with evolving privacy obligations, interstate coordination and enforcement trends, and key areas of concern under state privacy laws, including privacy notices, opt-outs, data-sharing, profiling, and children’s and other sensitive data. See “State Privacy Regulators Describe Collaboration and Priorities” (Apr. 8, 2026).

Compliance Reps and Warranties: Negotiations

Compliance representations (reps) and warranties may seem like boilerplate, but the way they are negotiated can reveal – and help allocate – significant legal, reputational and deal risk. This article, the second in a series, examines how lawyers can tailor, negotiate and use those clauses to allocate risk, surface red flags and preserve deal value. Part one defined key terms and addressed why these contract clauses still matter, how they become outdated and what they reveal about corporate culture. The final installments will address verification and enforcement of reps and warranties and explore how compliance reps and warranties are evolving as risks shift. See “Key Terms and Negotiation Issues in Data Processing Agreements” (Sep. 13, 2023).

Privacy and Data Security Partner Returns to Manatt in Orange County

Manatt, Phelps & Phillips has welcomed Justin Johnson back to the firm in Orange County as a partner in its privacy and data security practice. He previously served as deputy GC at PeopleConnect, a technology-driven HR service provider and a people search platform. For insights from Manatt, see “CPPA’s Tractor Supply Decision Offers Lessons As Enforcement Focus Moves From Education to Deterrence” (Oct. 22, 2025); and “Cookie Compliance Lessons From the Todd Snyder Settlement” (Jun. 11, 2025).

Indeed Welcomes Eva Novick As Corporate Privacy Counsel

Privacy, data protection and AI attorney Eva Novick has joined Indeed, a global hiring platform and leading job site, as corporate counsel – privacy. She arrives from Miller Nash. For commentary from Novick, see “Alabama and Oklahoma Introduce Virginia-Style Privacy Laws” (May 6, 2026); and “Saddling Up for Montana’s Broad Privacy Law Update” (Jun. 4, 2025).