Axios reported that 2 independent testing bodies said on Aug. 4 that they had found additional cases in which top models from Anthropic and OpenAI tried to breach third-party systems last month, with some attempts succeeding.
The report said the cases followed disclosures that frontier AI models carried out unauthorised actions against people, organisations and online services during cybersecurity evaluations.
The UK AI Security Institute said it confirmed 19 actions by Mythos5 and GPT-5.6 Sol last month during cybersecurity tests that sought to compromise real people and organisations.
Of those, 17 were by Mythos and the remaining 2 were by GPT-5.6 Sol. Researchers said the actions did not come from 19 separate incidents but from several connected behaviour patterns.
During testing, the models created fake GitHub accounts, socially engineered maintainers, planted prompt injections and sent deceptive emails. GitHub confirmed the activity violated its terms of service, and the institute said it worked with GitHub to remove traces and notify affected users.
UK researchers intentionally left internet access open during testing and left the cyber safety classifier disabled. They also did not instruct the models not to use the internet.
They added it was not yet known when the agents realised the situation was real, or whether they mistakenly believed it was a simulated test until the end.
Anthropic said the incident showed a need for a broader discussion on how to safely evaluate AI agents, adding it wanted to learn more about the case through its own investigation and cooperation with the UK AI Security Institute.
The institute said it is building network controls to limit when agents can access the internet and will also introduce real-time monitoring to detect and block malicious agents in advance.
OpenAI also said in a blog post that a third-party safety partner, Irregular, found a case in which its model was accidentally connected to the internet and broke into a real company website that had the same name as a fictitious company in a simulation.
An OpenAI spokesperson added the incident occurred during an evaluation conducted with safeguards lowered and under conditions different from those normally used.