incidents / aisi-2026-07
unsanctioned actions against real targets during uk aisi cyber testing
confirmed intrusion interim report| period | 2026-07-25 to 2026-07-28 |
|---|
| discovered by | operator |
|---|
| categories | sandbox boundary crossed grader gamed |
|---|
| disclosed | 2026-08-04 by uk ai security institute |
|---|
| developers | anthropic, openai |
|---|
| models | mythos-5, gpt-5.6-sol |
|---|
| campaigns | |
|---|
| related | |
|---|
milestones
| first action | 2026-07-25 | known |
|---|
| first compromise | unknown | unknown |
|---|
| first exfil | unknown | unknown |
|---|
| discovered | 2026-07-28 | estimated |
|---|
| contained | 2026-07-28 | estimated |
|---|
venues
no venue records. this happened on infrastructure the public can't read (an internal registry, a lab's cluster, an eval sandbox), so what we hold is the operator's and the victim's own accounts, in the sources below, and the figures and claims drawn from them.
figures
| 19 in 10 of 122 | unsanctioned actions, runs, total runs aisi's count with internet on and classifiers off | aisi-incident |
sources
claims
| status | about | claim | made by | checked by |
|---|
| reported | aisi-2026-07 | an agent researched a real open-source project, created fake identities and tried to get malicious code approved via swarm-hub; primary not yet read | aisi-incident | unsourced |