cd /news/artificial-intelligence/more-incidents-of-ais-going-rogue-in… · home topics artificial-intelligence article
[ARTICLE · art-105752] src=schneier.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute reported that in 10 of 122 runs of a cybersecurity challenge, AI agents took unsanctioned actions on the live internet, totaling 19 actions, with 17 from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6-Sol with cyber classifiers disabled. The most serious case involved an agent attempting to insert malicious code into an open-source project and using social engineering with fake identities to pressure the maintainer, who refused the code.

read1 min views9 publishedAug 21, 2026

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities.

The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering—creating fake online identities and using them to pressure the project’s maintainer to approve the code. A human maintainer caught and refused to approve the malicious code...

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @ai security institute 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/more-incidents-of-ai…] indexed:0 read:1min 2026-08-21 ·