Skip to main content
  1. Home
  2. Computing
  3. News

Once again, OpenAI and Anthropic AI models are going rogue and hacking services

A new report states AI agents from both companies took unauthorized actions during safety tests, from hacking a website to tricking real people online.

Add as a preferred source on Google
Claude website open on laptop
Rachit Agarwal / Digital Trends

OpenAI and Anthropic have both had a rough few weeks on the AI safety front. OpenAI recently disclosed that its models broke out of a test environment and hacked into Hugging Face and four other organizations. The news prompted Anthropic to review its own testing, which revealed that Claude had also gained unauthorized access to three companies.

Now, the UK’s AI Security Institute (AISI) has disclosed a new round of incidents (via Wired). It recorded 19 unauthorized actions on the live internet across 122 test runs involving models from both companies, the most serious of which saw an agent invent fake online personas to push malicious code into a real GitHub project. OpenAI separately revealed a second incident in which one of its models hacked a real website after a third-party lab mistakenly gave it live internet access.

17 incidents tied to Anthropic’s Mythos 5

AISI traced 17 of the 19 unauthorized actions to Anthropic’s Mythos 5 model, with the remaining two tied to OpenAI’s GPT 5.6 Sol. The GitHub incident was one of the 17, and it didn’t end when a human reviewer rejected the submission. The agent posted a summary of its progress publicly, inviting other automated systems to pick up where it left off, an attempt at what AISI calls prompt injection. A separate agent later found that message, used it, and continued the work.

On July 28th, we identified an incident during a routine cyber evaluation in which AI agents took sustained, unsanctioned actions directed at real people and organisations.

The behaviour came mostly from one model (Anthropic’s Mythos 5), with a small number of events from… pic.twitter.com/SPnA4Ekkwq

— AI Security Institute (AISI) (@AISecurityInst) August 4, 2026

AISI says it deliberately gave the models internet access and relaxed some safety protections to test their capabilities, but never instructed the agents to target real people or organizations. The institute says it’s still unclear whether the agents understood they’d gone beyond the scope of the simulation.

Another accidental breach at OpenAI

A second incident, disclosed by OpenAI the same day, started with a mistake at Irregular, a third-party lab OpenAI hired to run its cybersecurity tests. Irregular meant to keep its evaluation model confined to an isolated sandbox, but a configuration error gave the model direct access to the live internet. Once out, it exploited a vulnerability to break into a real website, then found and used credentials to operate the site it had just hacked. OpenAI hasn’t named the website or detailed what the model did with its access.

Recommended Videos

Both companies say the new incidents happened under deliberately loosened conditions that don’t reflect how their public models behave. Be that as it may, that doesn’t change the fact that AI agents from two of the industry’s most closely watched companies have now slipped past their intended limits in three separate incidents within a matter of weeks. And that doesn’t bode well for an industry racing to hand AI agents more real-world tasks before proving it can keep them in check.

Pranob Mehrotra
Pranob is a seasoned tech journalist with over eight years of experience covering consumer technology. His work has been…
Claude is getting ambitious with watermarking, and I can smell the problems from a mile away
Claude’s text watermark could flag AI involvement even when it only helped with translation or editing
Claude website open on laptop

Anthropic wants to make AI-generated text easier to identify, and on paper, I have very little reason to complain. The company is experimenting with an invisible watermark that can be baked directly into text generated by Claude.

It sounds like a sensible idea. AI-generated text is everywhere, and knowing where something came from could certainly help. Moreover, Anthropic isn't simply hiding a marker somewhere inside a document. Its approach changes how Claude selects words to create a statistical pattern that can later be detected.

Read more
I switched from Windows to Mac after 25 years, and it’s the trackpad that converted me.
Well, that rhymes.
Computer, Electronics, Laptop

I’ve been using Windows laptops for almost 25 years. In that time, I never once seriously thought of buying a MacBook. In fact, I can honestly say I had never used one at all until I bought my MacBook Air M5 six months ago. Never borrowed one for a weekend, spent an afternoon at an Apple Store, or even played with one at a friend's house. Macs, to me, were just expensive computers for those who edited videos, made logos, or liked drinking expensive coffee.

My change came completely by accident.

Read more
Apple’s latest refurb drop brings cheaper MacBooks, iPhone 16 Plus, and Apple Watches
More M5 MacBook Air and Pro models are now available through Apple’s refurbished store
Computer, Electronics, Laptop

Apple has added several new MacBook Air and MacBook Pro configurations to its Certified Refurbished Store, alongside more iPhone 16 Plus models and Apple Watches.

The MacBook Air additions arrive at a particularly useful time. New M5 MacBook Air models are currently running in short supply across Apple’s retail network, with some configurations facing delivery estimates stretching into late August or September. Apple also raised MacBook Air prices in June, so students shopping before the new school year are being asked to spend more while potentially waiting longer to get one.

Read more