AI incident #1633 ·

Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

What happened

Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (3)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

  1. Incident Report: unsanctioned agent behaviour during cyber testing
    aisi.gov.uk · AI Security Institute (United Kingdom) · AIID #7696
  2. What the latest rogue AI incidents should teach us
    transformernews.ai · Shakeel Hashim · AIID #7775

Who was involved

Alleged harmed party
Software Developers, Open Source Maintainers, Github Users

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries