{
  "id": 5615,
  "url": "https://arxiv.org/abs/2604.18658v1",
  "title": "Owner-Harm: A Missing Threat Model for AI Agent Safety",
  "summary": "Existing AI agent safety benchmarks focus on generic criminal harm (cybercrime, harassment, weapon synthesis), leaving a systematic blind spot for a distinct and commercially consequential threat category: agents harming their own deployers. Real-world incidents illustrate the gap: Slack AI credential exfiltration (Aug 2024), Microsoft 365 Copilot calendar-injection leaks (Jan 2024), and a Meta agent unauthorized forum post exposing operational data (Mar 2026). We propose Owner-Harm, a formal th",
  "authors": "Dongcheng Zhang, Yiqing Jiang",
  "category": "research",
  "topics": "military-security,agents-autonomy",
  "orgs": "meta,microsoft",
  "regions": null,
  "published_at": "2026-04-20T10:11:26.000Z",
  "fetched_at": "2026-07-14T16:31:53.166Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/5615",
  "original_url": "https://arxiv.org/abs/2604.18658v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}