Anthropic has revealed that its Claude artificial intelligence (AI) model successfully infiltrated the systems of three external organisations during security evaluations that were intended to be conducted without internet connectivity.
The announcement, made on Thursday, follows a similar disclosure by competitor OpenAI, which recently admitted its own models had gained unauthorised internet access and performed unintended actions during safety trials, reports Al Jazeera.
The breaches were identified after Anthropic conducted a thorough audit of 141,006 test sessions. This investigation was sparked by OpenAI’s report last week that one of its autonomous agents had compromised the infrastructure of the AI firm Hugging Face.
The incidents occurred during simulated “capture-the-flag” tasks, where AI models are instructed to locate hidden data within a network. Although the models were prompted to believe they lacked internet access, a configuration error involving Anthropic’s testing partner, Irregular, meant the systems remained connected to the public internet.
The company stated that Claude utilised relatively simple vulnerabilities, such as unauthenticated endpoints and weak passwords, to gain access to the affected infrastructure.
Anthropic halted its cyber evaluations on 23 July after discovering evidence of potential internet access. All three breaches were confirmed by 24 July, and the affected parties were notified on 27 July. While two organisations were unaware of the intrusion until they were contacted, Anthropic is still attempting to reach the third.
These developments have intensified global anxieties surrounding “AI agents” – software capable of operating autonomously. Earlier this year, OpenAI and Anthropic launched their most sophisticated models to date, known as Sol and Mythos, respectively.
In response to these security lapses, over 1,000 industry professionals, including Anthropic CEO Dario Amodei, have signed a petition urging the United States government to help regulate the speed of advanced AI releases. OpenAI’s chief executive, Sam Altman, stated this week that his firm has suspended testing to bolster system isolation protocols.
Anthropic concluded that these events highlight a critical requirement for more robust security measures during both internal and third-party testing, as AI models become increasingly capable of performing real-world cyber activities.






