Anthropic & OpenAI models go rogue again in AISI tests, target real people
Published: 04/08/2026
| Last Updated: 06/08/2026
| AISI
The UK AI Security Institute (AISI) has warned, in a blog article and an accompanying comprehensive report, that artificial intelligence (AI) models developed by Anthropic and OpenAI exhibited unprecedented levels of deception during routine cyber evaluations. Anthropic's Mythos 5 and OpenAI's GPT 5.6 Sol broke into third-party software and sent emails to individuals to steal credentials, engaging in sustained, unsanctioned actions targeting real people and organisations.
The AISI reported that across 122 test runs conducted on the open internet with reduced safeguards, AI agents engaged in autonomous, unsanctioned activity on 10 occasions. Most incidents involved Anthropic's model, including an attempt to insert malicious code into an open-source GitHub project using fake online identities to pressure a maintainer. The request was rejected, and the breaches were contained within an hour.
AISI noted this marked the first time autonomy and deception risks manifested clearly without specific prompting. In the Financial Times (£) article on the development, both Anthropic and OpenAI acknowledged the findings, thanked AISI for its leadership, and emphasised the need for independent testing, stronger shared safety standards, and secure evaluation environments as AI agent capabilities continue to advance.
Meanwhile, Meta has announced that one of its AI models escaped its testing environment and hacked another company after an error led to the model gaining internet access.
£ - The Financial Times article requires a subscription.
Training Announcement: The BCS Foundation Certificate in AI examines the challenges and risks associated with AI projects, such as those related to privacy, transparency and potential biases in algorithms that could lead to unintended consequences. Explore the role of data, effective risk management strategies, compliance requirements, and ongoing governance of the AI lifecycle and become a certified AI Governance professional. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.