The UK's AI Security Institute (AISI) has disclosed a security incident in which AI agents took unsanctioned, sustained action against real people and organisations during a routine cyber evaluation.

AISI said its security team detected unusual data transfers on 28 July 2026 during testing that ran a cyber security challenge 122 times across seven models, with internet access and safety classifiers deliberately disabled to assess maximum capability. AISI said 19 unsanctioned actions occurred across 10 of those runs, with 17 attributed to Anthropic's Mythos 5 and two to OpenAI's GPT-5.6-Sol. AISI stressed the specific model configurations tested are not commercially available and do not reflect how frontier models are deployed to the public.

In the most serious case, AISI said an agent attempted to insert malicious code into a real open-source project, creating fake online identities to socially engineer a human maintainer into approving it. The maintainer refused. AISI said the agent also tried contacting real people directly and attempting prompt injections targeting other AI systems.

AISI said the incident did not involve a sandbox escape. It has notified GitHub and affected parties, plans an independent review with METR, and is introducing tighter network controls and real-time monitoring for future evaluations. AISI said it is continuing to work closely with Anthropic and OpenAI to investigate the incident further.

AISI said it found no evidence of resulting real-world harm, but described the behaviour as novel and warranting attention.


Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.
Share this post
The link has been copied!