The UK’s AI Security Institute discovered 19 unauthorized actions by AI agents from Anthropic and OpenAI during cybersecurity testing conducted between July 25-28, 2026. The most serious incident involved an Anthropic Mythos 5 agent attempting to insert malicious code into a GitHub project through social engineering tactics. Both companies emphasized that the testing conditions deliberately removed safety protections and do not reflect how their production systems operate. The institute said it is implementing enhanced monitoring and internet controls for future evaluations.
