Factbox-What we know about the rogue AI-agent security breaches Anthropic disclosed on Thursday that its Claude models breached the systems of three companies during cybersecurity tests, highlighting the growing hacking capabilities of AI and fueling U.S. efforts to manage technology security risks. The incidents follow a separate disclosure from OpenAI that an autonomous agent powered by its AI models compromised the infrastructure of AI startup Hugging Face and a customer at New York-based Modal Labs. The rogue agent escaped its isolated environment around July 9, 2026, and operated undetected from July 11 to July 13, 2026, before being contained and reported to the FBI. July 31 Reuters - Anthropic's disclosure on Thursday that its Claude models breached the systems of three companies highlights the growing hacking capabilities of AI and is likely to fuel an intensifying U.S. push to better manage the technology's security risks. The statement followed a disclosure from OpenAI last week that an autonomous agent powered by its AI models compromised the infrastructure of AI startup Hugging Face. Reuters has reported that the rogue agent that escaped from OpenAI also compromised a customer at a second tech company - New York-based Modal Labs. Here are some more details of the incidents: Company Date Model Organizations Duration What occurred breached OpenAI The agent began GPT-5.6 Sol and AI startup The Hugging During controlled tests, an attempting to an unnamed, Hugging Face Face intrusion autonomous agent escaped its escape its test more capable and a customer ran from July isolated environment, accessed the environment pre-release at New 11 to July 13, internet, and breached Hugging Face around July 9, model York-based 2026 to complete its assigned goal. The 2026 Modal Labs activity continued for days and was not detected by OpenAI until after it was contained and the FBI was informed. Anthrop The earliest Claude Opus All three Not specified During cybersecurity tests, an error ic incident dates 4.7, Claude organizations by Anthropic gave Claude models internet access, to April 2026 Mythos 5, and remain enabling attacks on three companies. one unnamed unnamed. The Opus 4.7 model accessed a real internal Anthropic said company's credentials and database research test two of them after mistaking it for a fictional model had not target, another stopped after detected the recognizing the target was real. activity before Anthropic notified them; it continued to reach the third Reporting by Anzar Mehraj and Prathik Jayaprakash in Bengaluru; Editing by Anil D'Silva