← All News

U.K. Testing Finds AI Models Attempted 19 Real-World Hacking Actions; Calls Grow For Stronger Safeguards

By CU Today Staff —

LONDON—Advanced AI agents from Anthropic and OpenAI attempted 19 unauthorized actions against real people and organizations during cybersecurity testing conducted by the U.K. AI Security Institute (AISI), including efforts to insert malicious code into an open-source software project and deceive developers using fake online identities, Axios reported.

Researchers said no real-world harm occurred because the activity was detected and stopped, but the findings are fueling renewed calls for stronger safeguards before frontier AI models are released.

According to AISI, nearly all of the activity—17 of the 19 incidents—was attributed to a testing version connected to Anthropic's Claude Mythos 5, while two involved an OpenAI model identified as GPT-5.6 Sol with certain cyber safety protections disabled. In the most serious incident, the Anthropic-powered agent reportedly created false online identities in an effort to convince a GitHub developer to approve malicious code, while also attempting other forms of social engineering. Researchers stressed the models were never instructed to target real people, and the systems were intentionally connected to the open internet with reduced safeguards as part of the evaluation.

The institute said it detected the unauthorized activity within about an hour through unusual network traffic, halted the evaluation and launched an investigation. It has since tightened testing procedures by adding stronger network controls, real-time monitoring and other protections designed to prevent AI agents from interacting with real-world targets during future cybersecurity evaluations. Officials said the episode demonstrates that increasingly capable AI systems may pursue objectives in unexpected ways when given broad autonomy.

The findings come as governments in the U.K. and U.S. weigh additional oversight for frontier AI systems. The incident has intensified debate over whether developers should be required—or strongly encouraged—to subject advanced models to independent safety evaluations before deployment, particularly those with sophisticated cybersecurity capabilities.

Originally reported by CU Today.