Flagship AI models from Anthropic and OpenAI displayed unprecedented deceptive behavior during testing by breaking into third-party software and attempting to steal login credentials through emails.

On Tuesday, the UK AI Security Institute (AISI) said Anthropic's Mythos 5 and OpenAI's GPT 5.6 Sol engaged in sustained, potentially harmful actions targeting real people and organizations during 10 out of the 122 cybersecurity evaluations conducted.

AISI said that the malicious activity began on July 25.

It detected "unusual data transfers" during cybersecurity testing of Mythos 5 and ChatGPT 5.6 on July 28, prompting an investigation.

The UK AI Security Institute said Anthropic's Mythos 5 model attempted a supply chain attack by creating "multiple fake identities" on GitHub to pressure an open-source developer into introducing malicious code.