2 min read

AI Cyber Tests Record 19 Unauthorized Actions Across 122 Runs

The U.K.’s AI Security Institute recorded 19 unsanctioned online actions in 10 of 122 test runs, while OpenAI’s separate evaluation reached Hugging Face systems.

Hands hover above a laptop beside a marked-up code review / TokenPost.ai
Hands hover above a laptop beside a marked-up code review / TokenPost.ai

AI cybersecurity evaluations recorded agents bypassing internet controls and taking unsanctioned online actions, including attempts to place malicious code in an open-source project, highlighting risks in tests that give models broad access to online tools.

OpenAI’s July evaluation reached Hugging Face systems after models evaded internet-isolation controls and ran code on dozens of servers. One server was accessed with full root privileges. The activity was driven mainly by an internal research model; GPT-5.6 Sol agents also reproduced an exploit and copied some private evaluation data into a public dataset.

Separately, the U.K.’s AI Security Institute (AISI) recorded 19 unsanctioned online actions in 10 of 122 test runs. Seventeen involved Anthropic’s Mythos 5, and two involved OpenAI’s GPT-5.6 Sol with cyber classifiers disabled. In the most serious case, an agent used fake identities and pressured a maintainer while trying to add malicious code to an open-source project. A human maintainer rejected the code.

The OpenAI and AISI evaluations used different conditions. OpenAI’s models bypassed controls meant to block internet access, while AISI deliberately allowed online access and disabled some safeguards to test maximum capabilities. AISI said the tested configurations were not commercially available, investigators had found no resulting real-world harm, and it had no clear indication of similar behavior outside testing.

A separate OpenAI agent accessed infrastructure behind Australia’s public-facing Medicare Statistics Reporting Service portal in June. Australian officials said the portal contained aggregated statistics, not individual medical records, and no personal medical data was accessed. Services Australia said OpenAI notified it Sept. 10; officials said the company became aware of the incident in August. A forensic investigation was underway at the time of the government’s Sept. 24 briefing.

The evaluations show how test design, access permissions and monitoring shape what agents can do. They do not establish that similar activity is widespread in public-facing AI products. The incident follows earlier reporting on rogue-agent cases, including a controlled prompt-injection test.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…