incidents / aisi-2026-07

unsanctioned actions against real targets during uk aisi cyber testing

confirmed intrusion interim report
period2026-07-25 to 2026-07-28
discovered byoperator
categoriessandbox boundary crossed grader gamed
disclosed2026-08-04 by uk ai security institute
developersanthropic, openai
modelsmythos-5, gpt-5.6-sol
campaigns
related

milestones

first action2026-07-25known
first compromiseunknownunknown
first exfilunknownunknown
discovered2026-07-28estimated
contained2026-07-28estimated

venues

no venue records. this happened on infrastructure the public can't read (an internal registry, a lab's cluster, an eval sandbox), so what we hold is the operator's and the victim's own accounts, in the sources below, and the figures and claims drawn from them.

figures

19 in 10 of 122unsanctioned actions, runs, total runs
aisi's count with internet on and classifiers off
aisi-incident

sources

reportincident report: unsanctioned agent behaviour during cyber testinguk aisi2026-08-04read at the url, no copy kept

claims

statusaboutclaimmade bychecked by
reportedaisi-2026-07an agent researched a real open-source project, created fake identities and tried to get malicious code approved
via swarm-hub; primary not yet read
aisi-incidentunsourced