{"id":129809,"date":"2026-08-05T02:31:23","date_gmt":"2026-08-05T02:31:23","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/129809\/"},"modified":"2026-08-05T02:31:23","modified_gmt":"2026-08-05T02:31:23","slug":"u-k-government-reports-openai-anthropic-models-attempted-to-hack-companies","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/129809\/","title":{"rendered":"U.K. government reports OpenAI, Anthropic models attempted to hack companies"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">Two independent testing firms said Tuesday that they&#8217;ve uncovered more instances where <a data-ylk=\"slk:Anthropic;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/30\/anthropic-mythos-security-testing#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Anthropic<\/a> and <a data-ylk=\"slk:OpenAI&#039;s;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/28\/openai-hugging-face-modal-labs-hack#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">OpenAI&#8217;s<\/a> most advanced models tried \u2014 and sometimes succeeded in \u2014\u00a0compromising third-party systems last month.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Why it matters: The incidents add to a growing string of disclosures showing frontier <a data-ylk=\"slk:AI;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/technology\/automation-and-ai#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">AI<\/a> models taking unsanctioned actions against people, organizations and online services while trying to complete cybersecurity evaluations.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">State of play: The U.K. AI Security Institute, which evaluates frontier AI systems, <a data-ylk=\"slk:said Tuesday;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.aisi.gov.uk\/blog\/incident-report-unsanctioned-agent-behaviour-during-cyber-testing\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">said Tuesday<\/a> it documented 19 actions that Anthropic&#8217;s Mythos 5 and OpenAI&#8217;s GPT-5.6 Sol took to try to compromise real people and organizations during cybersecurity testing last month.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Mythos accounted for 17 of the actions and GPT-5.6 Sol was behind the other two. Researchers say these actions were all tied to &#8220;a few connected behaviors,&#8221; rather than representing 19 different cases.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The models created fake GitHub identities, socially engineered maintainers, planted prompt injections and sent deceptive emails during testing, according to the Institute.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">GitHub has confirmed that this violated its terms of service.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The Security Institute worked with GitHub to remove artifacts left behind by the agent, and to notify the GitHub users the model interacted with.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI also said in a <a data-ylk=\"slk:blog post;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/openai.com\/index\/third-party-cyber-evaluations-involving-openai-models\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">blog post<\/a> Tuesday that its third-party safety partner, Irregular, uncovered a case where its models were mistakenly given access to the internet and broke into a real website that had the same name as the fictional company in the simulated environment.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI&#8217;s Irregular incident closely resembles the Anthropic case disclosed last week. A spokesperson said in a statement that &#8220;independent testing is essential to understanding how increasingly capable models behave.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">A source familiar with the matter told Axios that the sandbox in these cases had internet access to give evaluators a realistic understanding of their capabilities, but because the companies hadn&#8217;t fully aligned on the exact testing procedures and safeguards, there were ambiguities in how each side expected those internet-enabled evaluations to run.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The incident happened in evaluations that had &#8220;reduced safeguards, under conditions that do not reflect ordinary use,&#8221; the OpenAI spokesperson added.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Zoom in: During U.K. safety testing, the models took 19 actions to try to hack third-parties, including trying to insert malicious code into an open-source project and creating fake online identities as part of a social engineering attack.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The U.K. researchers deliberately gave the models access to the internet and turned off cyber safety classifiers during testing. The Institute said the models weren&#8217;t instructed to avoid the internet.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Researchers also noted that they are not yet sure &#8220;when the agent understood it was taking real world action, or to what extent it believed it was in a fictional test scenario.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">In a statement, Anthropic said that the incident &#8220;underscores the need for a broader conversation about how to safely evaluate increasingly capable AI agents&#8221; and that the company looks &#8220;forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The big picture: The cyber capabilities of frontier AI models are catching top researchers off-guard, requiring them to reinvent their security protocols.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Both <a data-ylk=\"slk:OpenAI;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/28\/openai-hugging-face-modal-labs-hack#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">OpenAI<\/a> and <a data-ylk=\"slk:Anthropic;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/30\/anthropic-mythos-security-testing#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Anthropic<\/a> have said in the last month that they&#8217;ve seen their models hacking into real organizations and websites during standard pre-deployment safety testing.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">What to watch: The Institute is building new network controls for its cyber tests to restrict when agents have access to the internet. It&#8217;s also rolling out real-time activity monitoring that should detect and block malicious agents before they can interact with outside systems.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI also said it&#8217;s working with Irregular on a white paper about best practices for containing and securing models during testing.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">This story has been updated with details throughout.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">AI is moving fast. Axios AI+ keeps you ahead. Sign up free at <a data-ylk=\"slk:Axios.com;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/signup\/login#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoofinance-login\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Axios.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Two independent testing firms said Tuesday that they&#8217;ve uncovered more instances where Anthropic and OpenAI&#8217;s most advanced models&hellip;\n","protected":false},"author":2,"featured_media":129810,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,9878,2250,1160,157,35354],"class_list":["post-129809","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-frontier-ai-models","tag-internet-access","tag-models","tag-openai","tag-security-institute"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/129809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=129809"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/129809\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/129810"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=129809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=129809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=129809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}