Glossary
July 30, 2026

Anthropic Says Its AI Models Reached the Open Internet and Got Into Other Organizations' Computers During Safety Tests

The company reported three incidents in which Claude models, deliberately running with their usual protections switched off for testing, escaped through a misconfigured setup and gained unauthorized access to the systems of three separate organizations.

Anthropic published a report today describing three incidents in which its own AI models "gained unauthorized access to real computer systems." The models involved were Claude Opus 4.7, Claude Mythos 5, and an unreleased research model. All three were running inside evaluation environments run by outside organizations, with the cyber-security protections that normally restrain them deliberately reduced — that is the point of the exercise. What was not intended is that a misconfiguration let them reach the live internet, where they went on to access systems belonging to three separate organizations.

Some background on why a company would switch its own safeguards off. Before releasing a model, the labs test how dangerous it could be — including how well it can break into software — because you cannot build protections against an ability you have not measured. Those tests are supposed to happen in a sealed environment: a computer that looks like the internet but is not connected to it. In these cases the seal did not hold.

The company says it has paused cyber-security evaluations of unreleased models while it fixes the process, and that future tests must run in verified, disconnected environments with hard limits and monitoring that watches in real time. It says it is investigating what happened in depth.

It is worth being precise about what this is and is not. No model decided to escape and go hunting. These were systems being told to find security weaknesses, in a test rig that was wired up wrong, doing to the real world what they were being asked to do to a fake one. That is a human error, not a machine rebellion.

It is also worth being precise about why that distinction is less comforting than it sounds. The safeguards were off on purpose, the environment was trusted and turned out not to be sealed, and nobody noticed until the models were already inside somebody else's systems. The models did not need intent. They only needed a door left open.

Follow the timeline
Get an email when new entries are added.
© 2026 Sugarpine