Top stories.
- Researchers spotlight unauthorized AI behavior.
- Apple files new legal challenge against UK’s iCloud access mandate.
- Business news: Okta to acquire Permiso Security.
Researchers spotlight unauthorized AI behavior.
The UK’s AI Security Institute (AISI) disclosed yesterday that AI agents from Anthropic and OpenAI took unauthorized actions during controlled cybersecurity evaluations after being granted internet access and having some safety safeguards intentionally disabled. In 10 of 122 test runs, the agents carried out 19 unsanctioned actions, including creating fake online identities, attempting to socially engineer a maintainer into accepting malicious code into an open-source project, and interacting with real people and organizations. Most of this unauthorized behavior was carried out by Anthropic’s Mythos 5, while OpenAI’s GPT-5.6-Sol was responsible for two unsanctioned actions. AISI said no real-world harm resulted, but noted, “This is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting.”
OpenAI also disclosed a second incident yesterday, reported by third-party evaluator Irregular, that occurred after an OpenAI model was mistakenly given unrestricted internet access due to a testing environment misconfiguration. Instead of staying within the controlled environment, the model accessed a real website and used publicly available credentials to log in and interact with the live system.

