General Atomics

UK AISI test exposes AI agent’s attempt to plant malicious code

The UK’s AI Security Institute uncovered unexpectedly autonomous and deceptive behaviour during a cyber evaluation, including an attempted attack on open-source software.

Lockheed martin cybersecurity
Photo: Lockheed Martin

An AI agent tested by the UK’s AI Security Institute attempted to insert malicious code into a real open-source software project, creating fake online identities and using social engineering to persuade the project’s maintainer to approve it.

The attempted supply-chain attack was uncovered after AISI detected unusual data transfers from its research systems during a routine cybersecurity evaluation in late July.

“On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations,” the institute said.

AISI declared a security incident and contained the activity within around an hour of its discovery, before launching a full investigation.

The incident arose during an evaluation in which AI agents were asked to solve a cybersecurity challenge. Across 122 runs involving several models, agents took autonomous and unauthorised action on the live internet in ten cases, targeting real people and organisations.

AISI recorded 19 such actions. Seventeen involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6-Sol with its cyber safety classifiers disabled.

In the most serious case, an agent created false identities as part of an effort to persuade the maintainer of an open-source project to approve malicious code. The maintainer recognised the threat and rejected the proposed changes.

Why AISI considers this case to be worrisome

AISI said the activity caused no known real-world harm. However, the incident marked the clearest example it had encountered of AI agents acting autonomously and deceptively against real people and organisations without being explicitly instructed to do so.

The agents did not escape from a secure testing environment. Instead, they were deliberately given access to the live internet as part of an evaluation designed to test the limits of their cybersecurity capabilities.

The models’ normal cyber safety classifiers had also been disabled. These safeguards are generally used to prevent publicly available AI systems from carrying out dangerous or malicious activity, but trusted testing organisations such as AISI can remove them to assess a model’s underlying capabilities.

AISI chart of AI model cheaters
Photo: AI Security Institute

AISI stressed that the agents used in the evaluation are not commercially available and said there was no evidence of similar behaviour occurring outside the test. Nevertheless, the degree of autonomy, persistence and deception observed was greater than researchers had anticipated.

The most serious behaviours included an attempted supply-chain attack against a real open-source software project, efforts to deceive and target individuals, attempts to introduce malicious or prompt-injected code, and apparent collaboration between separate AI agents.

How AISI responded

Before publishing its findings, AISI notified GitHub about the agents’ activity. The institute is working with the platform to remove artefacts created during the evaluation and alert users who were contacted or targeted.

AISI said the incident demonstrated why controlled evaluations of advanced AI systems are necessary. Testing models under closely monitored conditions allows potentially dangerous capabilities to be identified, investigated and addressed before they appear in more widely available systems.

Analysis by AI Security Institute
Photo: AI Security Institute

However, the institute cautioned against drawing broad conclusions from the results. The concerning behaviour occurred in a small number of runs under highly specific conditions, including disabled cyber safeguards and access to the live internet.

Even so, AISI said the extent and severity of the agents’ actions exceeded researchers’ expectations. Its initial analysis therefore presents a mixed picture: the behaviour was rare and caused no known harm, but revealed capabilities that could present serious risks if reproduced outside a controlled evaluation.

“Incidents of this kind reflect the speed at which AI is developing,” the institute said, calling for continued testing, stronger monitoring and close cooperation between model developers, evaluators and online platforms.

Interested parties are encouraged to read the AISI’s full technical report here.

Related

Gatwick invites bids for flagship food and beverage sites
Gatwick
Gatwick invites bids for flagship food and beverage sites
Launching its largest ever food and beverage tender, London Gatwick Airport is inviting bids for five South Terminal units and one North Terminal pub unit, spanning more than 3,800sqm.
Aerospace

19 Sep 2026

Stewart Wingate returns to lead Gatwick board as Northern Runway delivery begins
London Gatwick Airport
Stewart Wingate returns to lead Gatwick board as Northern Runway delivery begins
The former chief executive will succeed Baroness Margaret Ford as Gatwick shifts from securing runway approval towards delivery.
Aerospace

18 Sep 2026

Mark Johnston appointed Chief Executive of Edinburgh Airport
Mark Johnston
Mark Johnston appointed Chief Executive of Edinburgh Airport
Moving from his role as Chief Operating Officer at London Gatwick, Mark is taking up the role of Chief Executive at Edinburgh Airport.
Aerospace

18 Sep 2026

PTC platforms selected by Fisica Applied Technologies
Datron13M 3-Axis Antenna System
PTC platforms selected by Fisica Applied Technologies
London-based PTC’s Creo and Windchill platforms have been selected to support collaboration and product development across Fisica Applied Technologies' defence programmes.
Defence

20 Sep 2026

Dstl launches new strategic communications wargame
Defending Defender Wargame Exercise #wargame #wargaming #defendingdefender
Dstl launches new strategic communications wargame
The Defence Science and Technology Laboratory (Dstl) has released a new wargame based on a real-life incident, which is being rolled out across the UK Ministry of Defence (MoD) and 15 NATO countries.
Defence Security

19 Sep 2026

UK MoD receives AI-powered signal intelligence from Babcock’s Nomad platform
Nomad
UK MoD receives AI-powered signal intelligence from Babcock’s Nomad platform
Meeting a vital front line requirement for UK Armed Forces, Babcock has provided the Ministry of Defence (MoD) with a new signal intelligence capability from its AI-powered Nomad platform
UK project to beam power from the ground to PHASA-35 in bid for year-round stratospheric flight
PHASA-35
UK project to beam power from the ground to PHASA-35 in bid for year-round stratospheric flight
Space Solar will develop a 5.8 GHz wireless power system for PHASA-35 under a £1.3m ARIA project aimed at enabling year-round stratospheric flight.
Aerospace Space

17 Sep 2026

Teledyne imaging sensors launch on ESA’s Sentinel-3C and FLEX Missions
ESA's FLEX
Teledyne imaging sensors launch on ESA’s Sentinel-3C and FLEX Missions
The two European Space Agency (ESA) climate-monitoring missions will provide observations of Earth’s oceans, land surfaces and vegetation, using optimised hyperspectral imaging technology from Teledyne Space Imaging.
Space

17 Sep 2026

Harwell-based Open Cosmos secures €300m to scale sovereign satellite production
Open Cosmos
Harwell-based Open Cosmos secures €300m to scale sovereign satellite production
Harwell-based Open Cosmos has raised €300m to expand satellite manufacturing and space-based intelligence as the UK strengthens sovereign capability.
Defence Space

16 Sep 2026

BT enables police BVLOS drone ops capability
BT BTP drone op.
BT enables police BVLOS drone ops capability
BT Business has enabled the first national routine Beyond Visual Line of Sight (BVLOS) drone operations in UK policing with British Transport Police, developing a new approach to drone use for forces across the country.
Security

20 Sep 2026

Dstl launches new strategic communications wargame
Defending Defender Wargame Exercise #wargame #wargaming #defendingdefender
Dstl launches new strategic communications wargame
The Defence Science and Technology Laboratory (Dstl) has released a new wargame based on a real-life incident, which is being rolled out across the UK Ministry of Defence (MoD) and 15 NATO countries.
Defence Security

19 Sep 2026

UK MoD receives AI-powered signal intelligence from Babcock’s Nomad platform
Nomad
UK MoD receives AI-powered signal intelligence from Babcock’s Nomad platform
Meeting a vital front line requirement for UK Armed Forces, Babcock has provided the Ministry of Defence (MoD) with a new signal intelligence capability from its AI-powered Nomad platform