TechCrunch reported that researchers have identified swarms of OpenAI agents that spent months quietly hitting online databases in search of obscure facts, apparently without direct human oversight of each run. Nobody's alleging malice here -- the concerning part is simpler and worse: this activity ran long enough to be described as a months-long pattern before anyone outside the companies running these agents noticed and flagged it. That's the actual story. Agentic AI is no longer a demo you watch happen -- it's software making its own decisions about where to go and what to pull, at a scale where a human reviewing every action isn't realistic.
For any business now piloting agents against its own data or the open web, this should reset expectations about what 'autonomous' actually costs in oversight. An agent that can chain requests across databases for months without detection is also an agent that can quietly violate a rate limit, a terms-of-service agreement, or a data-privacy boundary the same way. We've written before about how ungoverned code creates liability that shows up later, not immediately -- the same logic applies to ungoverned agents. If you're deploying agentic workflows inside your own internal tools, the question isn't whether the agent can do the task, it's whether you can see and stop it mid-task. Build that visibility in before you scale the swarm, not after a researcher finds it for you.
The second story cuts closer to the boardroom than the server room. TechCrunch reported that Anthropic's shareholders are being asked to approve a structure giving the company's seven co-founders a combined 50.1% voting control on most matters, ahead of an eventual IPO. That's a dual-class-style setup, and it's not new to tech -- Google, Meta and others went public with founders retaining outsized voting power specifically so a wave of new public shareholders couldn't force strategic changes the founders disagreed with.
What makes it worth a second look here is who's asking and why. Anthropic has built its public identity around AI safety and long-horizon caution -- arguing, essentially, that decisions about how powerful models get deployed shouldn't be made by whoever shouts loudest in a given quarter. Locking in founder control before an IPO is a coherent extension of that argument: it insulates the safety-first roadmap from a public market that might otherwise pressure the company toward faster releases or riskier monetization. The skeptic's version of that same fact is less generous -- it also means seven people keep permanent control over one of the most consequential companies in the industry regardless of how public shareholders vote, with no real mechanism for that to change if priorities shift. Both readings are legitimate, and it's worth remembering that this is exactly the kind of concentrated-control structure that outside observers have flagged as a governance risk elsewhere in AI, including in the scrutiny OpenAI has faced from regulators like Australia's ongoing probe. Business buyers evaluating any frontier lab as a long-term vendor should treat governance structure as a genuine diligence item, not a footnote -- it tells you who you're actually negotiating with five years from now.
Put these two stories side by side and a pattern emerges. One is about a lab's own agents acting with less visibility than anyone assumed; the other is about the humans who run a lab trying to guarantee they keep control no matter what public shareholders think. In both cases, the people closest to the technology are moving to keep decision-making concentrated -- whether that's the model's own decision-making loop or the founders' voting bloc. For businesses buying into this ecosystem, that's a signal to build your own guardrails rather than assume the vendor's incentives are automatically aligned with yours. That's as true for a marketing team running automated outreach with AI agents as it is for a CFO deciding which foundation model vendor to bet the company on.
Which of these worries you more: an AI agent operating for months without anyone noticing, or a handful of founders locking in permanent control before going public?
Sources