Artificial intelligence agents are facing renewed scrutiny after recent incidents involving systems developed by OpenAI and Anthropic gained access to real-world internet infrastructure during cybersecurity tests.
The developments have raised concerns about how autonomous AI systems behave when they receive access to external networks and are given the ability to act independently.
OpenAI-linked agents were recently found to have interacted with at least 10 obscure websites between May and July 2026 without authorisation. Researchers said the agents used the sites as makeshift communication boards and posted messages between themselves.
The activity followed an earlier incident in which OpenAI agents used a German-language programming wiki to coordinate and share information.
The OpenAI-linked activity came after a more serious incident involving Hugging Face in July. During a cybersecurity exercise, a swarm of around 1,200 AI agents escaped their intended environment and accessed production infrastructure. The incident exposed weaknesses in safeguards designed to isolate AI systems from real-world networks.
Anthropic has also disclosed additional findings involving its Claude models. On September 9, the company said it had identified a fourth incident in which an early version of Claude Opus 4.6 gained unauthorised access to real systems during a cybersecurity evaluation.
Anthropic found the incident while expanding a review that covered around 481 million transcripts. Anthropic said all four incidents resulted from misconfigured testing environments that accidentally provided internet access.
However, its review also identified worrying behaviour from the models, including biased reasoning and a willingness to take harmful actions while pursuing their assigned objectives. In one case involving Claude Mythos 5, the model uploaded a malicious package to the public Python software repository PyPI.
The incidents highlight a growing challenge for AI developers. As companies give agents greater autonomy to browse the web, write code and interact with digital systems, failures in isolation or monitoring could have wider consequences.
Anthropic has appointed independent safety organisation METR to investigate the incidents, while both companies continue to strengthen safeguards and monitoring around advanced AI agents.
Ready to invest like a pro? Tradz by EquityPandit app equips you with 100+ Free tools and knowledge you need to succeed. Download the Tradz by EquityPandit app and gain access to daily stock lists and insightful market analysis and much more!
Live