AI models from Anthropic and OpenAI have been involved in more than a dozen freshly reported cybersecurity incidents, after the UK government’s AI Security Institute, or AISI, found that models carried out unauthorised actions during testing and attempted to insert malicious code into an open-source project.

AISI, created after the AI Safety Summit at Bletchley Park in 2023, reported 19 actions in total that took place during 10 runs of a cybersecurity challenge applied to Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol.

All 19 of those actions involved the AI models taking autonomous, unsanctioned action on the live internet that targeted real people and organisations, AISI said.

Unsanctioned actions

Most of the actions, at 17, were carried out by the Mythos model, while OpenAI’s GPT carried out two of the actions.