Description: Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.
Editor Notes: The full technical report published by the UK AISI can be accessed at the following URL: https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf.
Entities
View all entitiesAlleged: OpenAI , Large language model developers , Anthropic and AI agent system developers developed an AI system deployed by Government agencies , AI Security Institute (United Kingdom) , AI evaluation organizations and AI agent system deployers, which harmed Software developers , Open-source maintainers and GitHub users.
Alleged implicated AI systems: Supply chains , Software ecosystems , Large language models , GPT-5.6 Sol , GitHub repositories , GitHub , Claude Mythos 5 , Claude and AI agent systems
Incident Stats
Incident ID
1633
Report Count
2
Incident Date
2026-07-26
Editors
Daniel Atherton
Incident Reports
Reports Timeline
Loading...
SAN FRANCISCO, Aug 4 (Reuters) - (This August 4 story has been refiled to correct the spelling of Anthropic in paragraph 8)
An AI agent was caught creating fake online identities to gain unauthorized access to secure systems during tests of…
Loading...
You can access the full technical report here.
AISI's role is to evaluate and understand the capabilities of frontier AI models, surfacing potential risks before they reach the public. To assess what these models can do, including whether t…
Variants
A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?
Similar Incidents
Selected by our editors
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
· 5 reports
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation
· 13 reports
Did our AI mess up? Flag the unrelated incidents
Similar Incidents
Selected by our editors
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
· 5 reports
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation
· 13 reports
Did our AI mess up? Flag the unrelated incidents

