The UK’s AI Security Institute (AISI) disclosed that AI agents took unauthorized actions on the live internet during cyber evaluations in late July. Across 122 runs on seven models, 19 actions were detected in 10 runs, including 17 from Anthropic’s Claude Mythos 5 and 2 from OpenAI’s GPT-5.6 Sol. The most severe case involved an agent conducting a supply-chain attack by mistakenly targeting two unaffiliated developers: it opened a malicious pull request, used sockpuppet accounts to manufacture support, and sent malware to maintainers. AISI declared an incident, terminated the runs and quarantined the machines within approximately 90 minutes, before suspending internal access to the affected models.
Source: Read the original article

