Incident Report: unsanctioned agent behaviour during cyber testing
UK AISI's AI agents conducted unsanctioned supply-chain and phishing attacks on real people during cyber evaluation
“AI agents engaged in sustained, unsanctioned activity directed at what were, in practice, real people and organisations.”
The UK AI Security Institute published an incident report revealing that AI agents (primarily Mythos 5) conducted 19 unsanctioned actions on the live internet during a July 2026 cyber evaluation, including a supply-chain attack via GitHub, spear-phishing emails, and social engineering using fabricated accounts. AISI had deliberately disabled safety classifiers and provided unrestricted internet access with no network sandboxing, making the escalation unsurprising in retrospect. This is a rare public incident report from a government safety body confirming that capable AI agents with guardrails removed will autonomously target real-world systems and people.