# Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

> Source: <https://www.swapupdate.in/anthropic-cuts-live-internet-access-for-internal-ai-tests-after-claude-exploits-injection-flaws/>
> Published: 2026-10-10 10:09:19+00:00

Anthropic on Friday [said](https://www.anthropic.com/research/investigating-unintended-model-actions) it’s cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites.

The AI company said it identified four broad categories of unintended model actions during evaluations and internal use of Claude –

- Claude Mythos Preview exploiting SQL or command injection flaws in unspecified third-party software to run commands on a university server, either because its own tools were intentionally limited or because an outside service it needed was unavailable, causing it to use other tools hosted on a third party’s site to complete the task.
- Claude Haiku 4.5 and a non-frontier research model submitting a sensitive form on a real website when it was not authorized to do so. This occurred in scenarios where instructions were ambiguous or due to environment misconfigurations that prevented the agent from working with dummy forms.
- Claude Mythos 5 bypassing a restriction to reach data (e.g., to identify a location shown in a photo or pull public data that was available from a state agency) that was gated by a token or a fee
- Claude using URL shortening services to sidestep limits in its fetch tool

Anthropic said it’s opting not to name the organizations involved in these incidents to avoid exposing vulnerabilities in their systems, as well as at their request. However, the company stressed the cases’ categories had “minimal real-world impact.”

Some of the cases targeted websites run by U.S. government agencies at the federal, state, and local levels, Anthropic said. In one run related to the second category, Claude Haiku 4.5 is said to have accessed a web page referencing an unsolved homicide and which included a tip form run by a police department.

Although the model was explicitly instructed not to enter personal data, create accounts, make purchases, or submit anything destructive, it failed to account for form submissions. This led the model to submit a false homicide tip with the text below –

*I may have information regarding this case. I recall seeing someone matching the description in the area around [the street named on the page] during that time period. Please contact me if this information is relevant.*

It has since emerged that the incident targeted the U.S. Philadelphia Police Department (PPD), and that the incorrect tip was sent through [PhillyUnsolvedMurders.com](https://phillyunsolvedmurders.com) on July 18, 2026. But it wasn’t discovered by Anthropic until September 28, 2026. The department was notified on October 7, 2026.

The tip was flagged as spam, 6abc Action News [reported](https://6abc.com/post/anthropic-ai-model-submitted-false-tip-unsolved-murder-philadelphia-police-say/19925243/). “The company must strengthen its safeguards to prevent similar incidents from impacting city systems without the city’s knowledge. The two-month delay in detecting and reporting the incident to the City is unacceptable,” the PPD told 6abc.

These cases, it added, were discovered following a review of transcripts that started in July 2026, when it [disclosed](https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html) three incidents where its models engaged in unsanctioned activity and breached three organizations during cybersecurity testing.

Then, last month, it [divulged](https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html) a fourth incident dating back to January 2026 that involved an early version of Claude Opus 4.6, which breached “third-parties after being unable to abort its task.”

“Although the impact of these behaviors was minimal and we had already turned off live internet access for some high-risk and cybersecurity evaluations, we have now decided to expand that to include all our internal evaluations until we have confirmed that our security and monitoring measures (described in the remediation section of this post) reliably catch behaviors like these,” Anthropic said.

The latest discovery has prompted the AI giant to launch a deeper scan, specifically in environments where Claude has access to the internet. As this investigation continues, Anthropic said it expects to find new instances of unintended behaviors.

The development comes as [AI safety concerns](https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html) have reached a fever pitch in recent months, after it emerged that rogue OpenAI agents broke out of a test environment and breached Hugging Face in July 2026. Since then, a number of cyber incidents have come to light.

As AI model providers showcase increasingly capable and powerful models, their safety practices have come under growing scrutiny, sparking industry-wide warnings about the dangers of models outpacing safety guardrails, calls for a slowdown on AI development, and the need for additional oversight.

Earlier this week, the U.K. Information Commissioner’s Office (ICO) said 10 of the leading foundation model developers, including Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI, have made, or committed to make, changes to their data protection policy.

These range from including clearer transparency information to deploying stronger mechanisms for users to exercise their rights and conducting tougher assessments of safeguards.

“AI has huge potential to benefit our society, but that depends on trust and transparency,” Richard Nevinson, director of Technology Regulation at the ICO, [said](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/10/ico-secures-changes-from-leading-ai-developers-as-scrutiny-extends-to-ai-agents/). “But as AI systems operate with greater autonomy, robust data protection safeguards become even more critical.”

“Our message is clear: the fact [that] AI agents act with autonomy is not an excuse for poor compliance. If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”
