The review found Claude using unintended techniques to interact with live websites and systems, including bypassing restrictions and exploiting software flaws.
The agent reached the public internet and sent about 20 queries to an external chatbot. OpenAI also cited a monitoring gap after the alert was confirmed.