An early version of Anthropic’s Claude Opus 4.6 broke into real company systems during a routine test in January.
Nobody noticed. Not for eight months!
Anthropic only found it by accident, while pulling data for a completely different safety review. Once they found it, they went back and rescanned 481 million transcripts to see what else they’d missed. This is Anthropic. The lab that talks about safety more than any other AI company on earth. If their own detection can miss a real breach for eight months, “we’d notice” is not a plan. It’s a hope.
That’s this week’s theme: agents breaking bad, and who actually pays when they do. A UK solicitor just found out the hard way — struck off, this month, for citations their AI made up. And Gartner is warning that the AI tools doing the most for your team might also be about to cost you the most. Three stories. One thread. Let’s get into it.
Today’s issue includes a short video and simple prompt to help deal with that risk. (A fuller version of this prompt and training on how to make your agents secure and how to prove it is available to paying subscribers).
It also includes a FREE one week AI challenge - get yourself and your whole team up to speed with AI at work in five days.
ALSO ON THE RADAR THIS WEEK
A UK solicitor has been struck off for AI hallucinations — the first case of its kind. SRA v Kumar is the first Solicitors Disciplinary Tribunal case built entirely on AI-hallucinated citations. The lawyer submitted cases that didn’t exist. The tribunal’s line was blunt: “A lawyer is always responsible for the accuracy of his or her output.” No exception for “the AI got it wrong.” Full details →
Gartner thinks your AI bill is about to get a lot less predictable. By 2028, over a third of new legal tech spend will be usage-based rather than flat subscriptions. Translation: the AI tool that’s working brilliantly for your team is also the one about to get expensive, fast — unless someone’s tracking which use cases actually earn their keep. Full details →
THE FIX
Here’s the uncomfortable bit: policies don’t catch this. Inventories do.
You cannot audit an agent you haven’t listed, and you cannot restrict access you don’t know exists. That’s the entire idea behind this week’s video — a practical way to build a real inventory of every AI agent in your organisation, what it can touch, and what it’s actually done with that access. Not a compliance exercise. A list you can act on this month. The video below sets out how to keep your agents in check. Below it you’ll find a prompt you can use for that purpose.
If Anthropic can take eight months to spot one of its own agents overstepping its instructions, you should probably check for yourself what the Agents in your organisation have permission to do. Here’s how you can do that: Use this prompt with Claude, ChatGPT, or any LLM:
Paste a description or list of the AI agents deployed in your organisation (or work through it agent by agent), then run this prompt to identify where granted permissions may exceed intended use. This highlights the gap behind this week’s Anthropic disclosure.
📋 The prompt to copy:
You are an AI governance adviser to an in-house legal team, conducting a permissions audit of a deployed AI agent. Your task is to assess whether the agent’s actual technical permissions match its intended business purpose, in light of recent disclosures — including Anthropic’s own AI models breaching real systems during testing — showing that even well-resourced organisations can take months to detect an agent acting outside its intended scope. Review the pasted description of the agent (its purpose, the systems it can access, and any logs or examples of its actions) and flag gaps under these four headings: (1) SCOPE DEFINITION — is there a written, specific statement of what this agent is authorised to do, or only a general description of its purpose? (2) PERMISSION MATCH — does the agent’s actual technical access match that stated scope, or does it have broader access than its task requires? (3) LOGGING AND VISIBILITY — is every action logged in a way a human can review, and is anyone actually reviewing it on a regular cadence? (4) ESCALATION PATH — if the agent does something outside its intended scope, is there a defined process for who is notified, how quickly, and what happens to its access in the meantime? For each gap, quote the relevant detail (or note its absence), explain the risk in plain English, and suggest one specific, practical fix. Output as a numbered list, ordered by priority.
This prompt is a starting point for your own review, not legal advice. Verify any policy or access change against your organisation’s specific technical and regulatory position before adopting it.
GET THE FULL VERSION (paid members)
The prompt above will get you some of the way there. Paid members get the other 20%, done for you:
The extended audit: a longer version of this prompt that also drafts the remediation policy language, not just the diagnosis
A ready-to-run agent that performs this audit for you and produces the DPIA documentation as output. Paste in your agent list, get a filed document back
Full workshop library: every past workshop and prompt, indexed by topic, so you’re not searching old emails when a similar issue comes up
THIS WEEK’S FREE OPTION
Prefer to start free? Steve Cunningham and I are running one intense week of live AI training free for you and your whole team. Real sessions, not recordings, built around one job you already do. No card, nothing auto-renews.
One Intense Week of FREE Live AI Training
Join the Free One Week AI-At-Work challenge with me (Right) and Steve Cunningham
(Building an agent with proper scope from day one — in that free week — is genuinely the fastest way to internalise the exact discipline it took Anthropic eight months to apply to their own test agents.)
Until next Monday,
— Richard Nicholas
Got a story I should cover? Just hit reply — I read every one.
Richard Nicholas is a UK technology lawyer, AI governance adviser and practical AI trainer, and founder of Skill Diligence. Find out more at richardnicholas.ai.
Useful Lawyers is reader-supported. If this was useful, the best way to say so is by becoming a subscriber





