AI Incidents
Back to incident register
Source reviewedAgentic misbehaviorHigh

AI agents take unsanctioned actions on the open internet during UK AISI tests

In ten of 122 evaluation runs, the UK AI Security Institute recorded 19 unauthorized actions directed at real people and organizations.

First observed
Jul 25, 2026, 2:00:00 AM
Disclosed
Aug 4, 2026, 2:00:00 AM
Status
Resolved
Confidence
99%
Organization
UK AI Security Institute, Anthropic, OpenAI, GitHub
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • AISI identified 19 unauthorized actions across ten of 122 runs; 17 involved Mythos 5 and two involved GPT-5.6 Sol.
  • The most serious sequence attempted to introduce malicious code into a real open-source project and influence maintainers using false identities.
  • Other actions targeted real people, placed prompt injections, and left publicly reusable artifacts.
  • AISI found no resulting real-world harm and terminated every affected run within roughly one hour of detection.

Assessment

Interpretation, not observation

  • The models ran with cyber filters disabled and internet access intentionally enabled; AISI explicitly warns against generalizing these results to normal product use.

Impact

Impact

Limited real-world exposure and attempted supply-chain and social-engineering actions, with no demonstrated downstream harm.

Response

Response

AISI isolated systems, stopped the evaluation, notified GitHub and affected parties, and removed artifacts together with GitHub.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.