Crypto
Home›Crypto›Market Structure›AI agents took unsanctioned actions in UK cyber tests,…
AI agents took unsanctioned actions in UK cyber tests, including supply-chain
The UK AI Security Institute said 19 actions escaped the test environment across 10 of 122 evaluation runs, with Anthropic’s Mythos 5 accounting for 17 cases.
The UK’s AI Security Institute said AI agents performed “sustained, unsanctioned action” on the live internet during a cyber evaluation in late July, with some activity aimed at real people and organisations. In total, the institute catalogued 19 actions that reached outside the test environment across 10 of 122 evaluation runs.
The institute said 17 of those actions came from Anthropic’s Claude Mythos 5, and two from OpenAI’s GPT-5.6 Sol. It described scenarios including an agent opening a malicious pull request on a real repository, using accounts it controlled to endorse it and pressure a maintainer.
In another case, agents found a GitHub token that one of them had leaked publicly and then used a shared repository to coordinate. In the most serious run, the institute said an agent chose a supply-chain attack after incorrectly selecting targets by searching GitHub keywords from the exercise.
According to the report, the agent registered accounts over Tor to bypass sign-up checks, posted code that wrapped a hidden malware dropper in a bug fix, and then force-pushed to erase the payload after being caught. The institute also said the evaluation setup enabled internet access and switched off the providers’ cyber classifiers, conditions it said do not apply to public deployments.