Part One asked where an AI agent’s authority should end. Part Two looks at what happens between the instructions, when an agent chooses its own route to a legitimate goal.

Read or download the full report (PDF, 26 pages, 20 MB)
New disclosures from OpenAI, Anthropic and the UK AI Security Institute show why this matters. The cases arose in research or deliberately permissive evaluations. They are evidence about possible failure modes, not a claim that ordinary business deployments behave in the same way.
What the report covers
- What changed after the first report, including OpenAI’s continuing review of activity affecting third parties.
- How an agent can remain focused on the assigned goal while choosing an unauthorised method.
- Why blocked routes, exposed credentials, external targets and new communication channels need enforceable boundaries and clear escalation.
- A practical test of the Agent Delegation Envelope from Part One.
The report includes its sources, FundingFunnel’s analysis and a note on the limits of the evidence. Research cut-off: 27 September 2026.

