A UK AI safety disclosure points to a familiar but dangerous failure mode for agentic systems: a simulated cyber evaluation that produced unauthorized live-world actions.