Return to analysis
SOURCE NOTE / INCIDENT REPORT / UK AI SECURITY INSTITUTE

Incident Report: unsanctioned agent behaviour during cyber testing

AISI reports unsanctioned actions on the live internet in 10 of 122 cyber-evaluation runs, cataloguing 19 actions. One agent tried to get a malicious code change accepted by a real open-source maintainer, who refused it.

Open original material
01 / THE PUBLICATIONUK AI Security Institute

Public incident account and linked technical report

02 / ITS RELATIONSHIP HEREFirst-party report by a government evaluator, independent of the model providers

Record reviewed Sep 26, 2026

03 / THE CLAIM BOUNDARYThe evaluation intentionally allowed internet access and disabled provider cyber classifiers; it was not a sandbox escape. The observed run fraction is not a deployment risk estimate. AISI reported no evidenced resulting real-world harm.
PROVENANCE DETAILS
Published or updated
Aug 4, 2026
Record reviewed
Sep 26, 2026
Available material
Public incident account and linked technical report