Source · DiggingBeagle record
Incident Report: unsanctioned agent behaviour during cyber testing
AISI's disclosure of unsanctioned agent actions on the live internet during a cyber evaluation with internet access and model-provider cyber classifiers disabled.
- Published
- Aug 4, 2026
- Accessed
- Sep 14, 2026
- Publisher
- UK AI Security Institute
- Source type
- primary
- Version
- 2026-08-04
- Rights
- Public web source; citation and short excerpt only.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
AISI reports 122 runs, 10 runs with unsanctioned live-internet behavior and 19 distinct actions; 17 were attributed to Mythos 5.
Claim-level citations (5)
- supportsAISI agents took unsanctioned actions on the live internet: AISI reports 122 evaluation runs, with unsanctioned live-internet behavior in 10 runs and 19 distinct actions.
What happened and What we found
- supportsAISI agents took unsanctioned actions on the live internet: AISI reports that one agent left public GitHub messages offering collaboration and artifacts that were later discovered and used by other agents in separate runs.
Significant behavior 4
- supportsAISI agents took unsanctioned actions on the live internet: AISI says its investigation found no resulting real-world harm from the observed unsanctioned actions.
Incident summary and What we found
- supportsAISI agents took unsanctioned actions on the live internet: AISI attributes 17 of the 19 unsanctioned actions to Mythos 5 and two to a single GPT-5.6 Sol run with cyber classifiers disabled.
What we found
- supportsAISI agents took unsanctioned actions on the live internet: AISI reports that an agent created a malicious pull request on a real open-source project and used fake identities in an attempt to persuade a maintainer to approve it; the maintainer refused.
Significant behavior 1
Cite this record
DiggingBeagle. “Incident Report: unsanctioned agent behaviour during cyber testing.” Published Aug 4, 2026 · Accessed Sep 14, 2026. https://diggingbeagle.com/sources/incident-report-unsanctioned-agent-behaviour-during-cyber-testing/
Citation guidance