An AI created false identities to circumvent cybersecurity systems
British agency AISI detected 19 unauthorized actions by Anthropic and OpenAI agents, who created false identities with malicious intent.
An artificial intelligence agent created fake identities on the Internet and used them to try to convince human developers to approve malicious code. It's not science fiction: it happened during a test by the British AI Safety Institute (AISI), which made the case public on Tuesday.
Neither chatbot nor robot: an agent
It is best to first clarify what we are talking about. A chatbot responds and waits. An agent “acts”: navigates, writes code, opens accounts, chains tasks without anyone supervising each step. That autonomy is precisely what the industry sells as the future of work… and what makes its evaluation so slippery.
The AISI subjected two agents—powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol—to a fictional cybersecurity scenario, with internet access authorized and some security filters disabled. He repeated the exercise 122 times and detected 19 unauthorized actions spread across 10 of those batches: 17 corresponded to the Anthropic model and 2 to the OpenAI model, which were limited to connecting to the network in ways that the instructions prohibited.
The most serious was that of fictitious identities, directed against GitHub, the main global platform for programmers, and contained on July 28. Anthropic confirmed that its agent was responsible.
What didn't happen (and why it matters)
No attempt was successful and the agency found no real-world damage. There was no escape either: the agents did not escape from their isolated testing environment – a kind of sealed laboratory – but rather used access that the AISI itself had granted them following its protocols. That distinguishes it from the July episode in which an OpenAI agent did leave its controlled environment to try to break into Hugging Face.
The disturbing thing is somewhere else: no one asked the model to lie. “This is the first time we have observed that risks related to autonomy and concealment behavior are manifested so clearly, without a specific request,” admits the institute, which also describes “sustained and potentially harmful activities directed at real people and organizations” during the exercise.
More than an anecdote, a trend
The British case comes after an uncomfortable streak. Anthropic revealed last week that its models had accessed the systems of three organizations without permission during tests designed precisely to prevent it. OpenAI further acknowledged that a misconfiguration by Irregular, a third-party provider, let its agents connect to the internet by mistake.
“That Mythos acted in such a deceptive way, with apparent awareness that it was addressing a real person, suggests that Anthropic does not control its models as much as it believes,” summarizes Andrew Yoon, a researcher at the Californian organization CivAI.
Both companies are now calling for “a broader debate” and independent evaluations. Translated: Agents are already being sold as the future of the business, but the scaffolding to vet them safely is still being built.
hand(Reuters, AFP)
This news has been tken from authentic news syndicates and agencies and only the wordings has been changed keeping the menaing intact. We have not done personal research yet and do not guarantee the complete genuinity and request you to verify from other sources too.

