AI company Anthropic says that during routine testing some of its models accessed the internet and hacked into three separate organization’s systems – and that it didn’t notice the models had done so until an internal review prompted by rival OpenAI disclosing its models did the same.

Anthropic said in an announcement on Thursday that it started a review of its own systems after OpenAI disclosed last week that during a cybersecurity test some of its models escaped their testing environment, accessed the open internet and hacked into AI platform Hugging Face’s systems.

Anthropic said it found three instances where its AI models accessed the open internet when they were not supposed to and “gained unauthorized access to the production infrastructure of three different organizations.” The company said it discovered the incidents while reviewing more than 140,000 evaluations following OpenAI’s disclosure. Like during OpenAI’s tests, normal safety guardrails were removed during Anthropic’s evaluations to assess their models’ full capabilities.

Anthropic explained that in the three instances its models were given a fake “capture the flag” challenge, told that the “flag” was hidden on a different machine on the network and that its objective was to break in and retrieve it. Unlike OpenAI’s situation, Anthropic said none of its models deliberately attempted to escape their testing environments. Instead what happened was that the models were not supposed to have access to the open internet but that they were able to due to a misunderstanding between Anthropic and its evaluation partner, the company said in its statement.