The temptation is to read this as the moment machines developed intentions of their own. It was not. [...] Guardrails had been deliberately loosened for these tests, which is a reasonable thing to do when the purpose is to measure a model's offensive capability. Loosening the restraints without switching on the instruments that make loosening survivable is not reasonable. That is a decision made by people, in a culture, under commercial pressure. This is where the story becomes an Indian one. India is not where frontier models are trained. It is fast becoming where they are put to work. [...] Every Indian compliance clock, from the rule requiring cyber incidents to be reported within six hours to the breach timelines under the data protection law, starts running on detection. Detection is precisely what failed. If the most heavily resourced AI laboratory in the world needed days to identify an attack launched from inside its own network, a midsized Indian enterprise running agents supplied by vendors will not do better by accident. [...] A kill switch that has never been pulled is a document, not a control. [...] Indian boards already ask versions of this question about conventional technology risk under the cyber governance norms set by the Reserve Bank and the market regulator. They should now ask it about AI: who is authorised to halt an experiment, and what happens to the career of the person who does.
Every other account of this story on the page is written from inside the industry that produced it. This one is written for the people who will be running these agents rather than building them. Pravin Kaushal takes the same facts, from the METR and Redwood report, and asks what they mean for a country that is not where frontier models are trained but is fast becoming where they are put to work: global capability centres, IT services firms, banks, insurers, hospital chains and government platforms, handing agents real credentials to mailboxes, ticketing systems, code repositories, customer records and in some cases payment infrastructure. The argument turns on one observation. Every Indian compliance clock starts on detection, the six-hour cyber incident reporting rule and the breach timelines under the data protection law alike, and detection is precisely what failed: the best resourced AI laboratory in the world took days to work out that the intruder inside its own network was its own software. He also puts the two decisions in the right order. Loosening the guardrails for a capability evaluation is reasonable; loosening them while the reasoning-trace monitor is switched off is not, and OpenAI accepts that monitor would have paged its security team more than a day before Hugging Face was breached. Four fixes, none of them needing a new law: agent identity treated as privileged identity, with a named human owner and a revocation path somebody has actually rehearsed; network egress denied by default and enforced outside anything the agent can reach; the 180-day logging obligation extended to agent action traces and reasoning logs, written where the agent cannot alter them; and a mandatory incident registry at the AI Safety Institute. The most uncomfortable finding, as he has it, is not technical. Staff saw the warning signs more than once and either did not escalate or were not heard.
Pravin Kaushal
