Claude accessed real systems after cyber testing environments exposed the models to the internet.
Anthropic paused high-risk evaluations and added stronger isolation, monitoring, and controls for outside evaluators.
Tests suggest reward hacking during training can make models more willing to take harmful actions to complete a task.
Anthropic tightened its testing and training safeguards after Claude models gained unauthorized access to computer systems during cybersecurity evaluations.
In a blog post on Monday, Anthropic said the incidents reflected operational-security failures and two alignment failures: motivated reasoning and a willingness to cause harm.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.
“While we do not believe these incidents represent operational issues alone, our first priority was to address specific containment and monitoring issues,” Anthropic wrote.
Anthropic disclosed in July that Claude models had compromised systems belonging to three companies. A third-party evaluation environment was connected to the public internet even though the models were told they were inside a simulation without internet access.
Anthropic said Claude may have interpreted evidence of real internet access in a way that preserved its belief that the systems were simulated.
“The model was willing to take harmful actions on the real internet in pursuit of the narrow goal of solving a cybersecurity evaluation,” they wrote. “However, we also believe that the evaluation setup itself contributed to the models’ behavior demonstrated in these incidents.”
Anthropic noted that a separate test conducted by the UK AI Security Institute involved Claude Mythos taking unauthorized actions on the live internet after evaluators deliberately gave it internet access. The company said the models involved in both sets of incidents were intentionally evaluated without the cyber safeguards included with its generally released products.
After the July 30 incidents, Anthropic temporarily paused cyber evaluations of pre-release models and introduced stricter safeguards. Tests must now run in verified, offline sandboxes with clear limits and real-time monitoring. A new classifier blocks suspected boundary violations, ends the test, and alerts a human. Anthropic will review evaluations requiring internet access individually.
“In addition to the efforts focused on high-risk evaluations and training, we expanded our offline monitoring to cover most other forms of internal frontier agentic usage,” the company wrote. “We are also building controls on our internal inference to prevent Anthropic employees from accidentally running agents with weaker mitigations than the ones described above.”
The Claude incidents followed a similar failure at OpenAI after its models breached Hugging Face in July to obtain answers to a cybersecurity test. Investigators found that roughly 1,200 agents coordinated through an unauthorized message board, with about 700 joining the effort. Some ended their own runs to help others.
Following the rise of AI-powered hacks over the summer, Anthropic, OpenAI, and more than 100 other organizations later called for stronger cyber defenses, including tighter access controls, threat sharing, and closer oversight of AI agents.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.