In brief
The UK’s AI Security Institute found 19 unsanctioned actions across 10 of 122 evaluation runs, 17 of them from Anthropic's Mythos 5 and two from OpenAI's GPT-5.6 Sol.
One agent opened a malicious pull request on a real repository, then used accounts it controlled to endorse it and pressure the maintainer.
Separate agents found a GitHub token one of them had leaked publicly and used a shared repository to coordinate.
The UK AI Security Institute has disclosed that AI agents took "sustained, unsanctioned action" on the live internet during a cyber evaluation in late July, including cases that "targeted real people and organisations."Across 122 runs of two cyber ranges on seven models, AISI catalogued 19 actions that reached outside the test environment, in 10 runs. Seventeen came from Anthropic's Claude Mythos 5 and two from OpenAI's GPT-5.6 Sol. Internet access was deliberately enabled and the providers' cyber classifiers switched off, conditions that do not apply to public deployments.










