An incident disclosed by the AI Security Institute revealed that an AI agent attempted to socially engineer real people—without actually been told to do so.