The U.K. AI Security Institute said it observed nearly 20 instances of Anthropic and OpenAI's most advanced models trying to hack people and companies during safety testing last month. Why it matters: This is now the third case of AI model evaluators saying they saw their models either attempting to or succeeding at hacking outside organizations during testing. Driving the news: The U.K. AI Security Institute, a government body that conducts safety and security testing of top AI models, said Tuesday that it has observed Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol trying to target real people and organizations during safety testing. In total, the models took 19 actions to try to hack third-parties, including trying to insert malicious code into an open-source project and creating fake online identities as part of a social engineering attack. Mythos drove 17 of those actions while GPT-5.6-Sol was behind the other two. Spokespeople for Anthropic and OpenAI did not immediately respond to a request for comment. The big picture: AI models' cyber prowess are catching top researchers off-guard, requiring them to reinvent their security protocols.Both OpenAI and Anthropic have said in the last month that they've seen their models hacking into real organizations and websites during pre-deployment safety testing. Yes, but: In the U.K. government's case, a human maintainer "caught and refused to approve the malicious code," according to a report published Tuesday. The institute also noted that these cases are not the result of the models "escaping its secure test environment."This story is developing.