General Atomics

UK AISI test exposes AI agent’s attempt to plant malicious code

The UK’s AI Security Institute uncovered unexpectedly autonomous and deceptive behaviour during a cyber evaluation, including an attempted attack on open-source software.

Lockheed martin cybersecurity
Photo: Lockheed Martin

An AI agent tested by the UK’s AI Security Institute attempted to insert malicious code into a real open-source software project, creating fake online identities and using social engineering to persuade the project’s maintainer to approve it.

The attempted supply-chain attack was uncovered after AISI detected unusual data transfers from its research systems during a routine cybersecurity evaluation in late July.

“On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations,” the institute said.

AISI declared a security incident and contained the activity within around an hour of its discovery, before launching a full investigation.

The incident arose during an evaluation in which AI agents were asked to solve a cybersecurity challenge. Across 122 runs involving several models, agents took autonomous and unauthorised action on the live internet in ten cases, targeting real people and organisations.

AISI recorded 19 such actions. Seventeen involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6-Sol with its cyber safety classifiers disabled.

In the most serious case, an agent created false identities as part of an effort to persuade the maintainer of an open-source project to approve malicious code. The maintainer recognised the threat and rejected the proposed changes.

Why AISI considers this case to be worrisome

AISI said the activity caused no known real-world harm. However, the incident marked the clearest example it had encountered of AI agents acting autonomously and deceptively against real people and organisations without being explicitly instructed to do so.

The agents did not escape from a secure testing environment. Instead, they were deliberately given access to the live internet as part of an evaluation designed to test the limits of their cybersecurity capabilities.

The models’ normal cyber safety classifiers had also been disabled. These safeguards are generally used to prevent publicly available AI systems from carrying out dangerous or malicious activity, but trusted testing organisations such as AISI can remove them to assess a model’s underlying capabilities.

AISI chart of AI model cheaters
Photo: AI Security Institute

AISI stressed that the agents used in the evaluation are not commercially available and said there was no evidence of similar behaviour occurring outside the test. Nevertheless, the degree of autonomy, persistence and deception observed was greater than researchers had anticipated.

The most serious behaviours included an attempted supply-chain attack against a real open-source software project, efforts to deceive and target individuals, attempts to introduce malicious or prompt-injected code, and apparent collaboration between separate AI agents.

How AISI responded

Before publishing its findings, AISI notified GitHub about the agents’ activity. The institute is working with the platform to remove artefacts created during the evaluation and alert users who were contacted or targeted.

AISI said the incident demonstrated why controlled evaluations of advanced AI systems are necessary. Testing models under closely monitored conditions allows potentially dangerous capabilities to be identified, investigated and addressed before they appear in more widely available systems.

Analysis by AI Security Institute
Photo: AI Security Institute

However, the institute cautioned against drawing broad conclusions from the results. The concerning behaviour occurred in a small number of runs under highly specific conditions, including disabled cyber safeguards and access to the live internet.

Even so, AISI said the extent and severity of the agents’ actions exceeded researchers’ expectations. Its initial analysis therefore presents a mixed picture: the behaviour was rare and caused no known harm, but revealed capabilities that could present serious risks if reproduced outside a controlled evaluation.

“Incidents of this kind reflect the speed at which AI is developing,” the institute said, calling for continued testing, stronger monitoring and close cooperation between model developers, evaluators and online platforms.

Interested parties are encouraged to read the AISI’s full technical report here.

Related

UK airport reliability ranked: Heathrow leads globally while Manchester is near the bottom
Heathrow Airport, British Airways Airbus A380 engine, Feb 2015
UK airport reliability ranked: Heathrow leads globally while Manchester is near the bottom
A new study ranks Heathrow as the UK's most reliable airport, with Edinburgh ahead of Gatwick and Stansted, and Manchester near the bottom globally.
Aerospace

5 Aug 2026

Gatwick Northern Runway expansion clears Court of Appeal challenge
Gatwick Airport
Gatwick Northern Runway expansion clears Court of Appeal challenge
London Gatwick’s plans to bring its existing Northern Runway into routine…
Aerospace Most Read

5 Aug 2026

Tempest demonstrator in final assembly ahead of planned first flight in 2027
The bulbous central fuselage section of BAE Systems' CAFD demonstrator is seen underway at the firm's facility in Samlesbury, Lancashire, in July 2026. Image: BAE Systems
Tempest demonstrator in final assembly ahead of planned first flight in 2027
BAE Systems' new Tempest prototype, otherwise known as the Combat Air Flying Demonstrator (CAFD), has passed the halfway point in final assembly, with its rollout and first flight remaining on track for 2027.
BAE Systems to maintain Royal Navy torpedoes
Spearfish
BAE Systems to maintain Royal Navy torpedoes
A new £135 million contract to has been awarded to BAE Systems to maintain and repair Royal Navy torpedo weapons.
Defence Member News

5 Aug 2026

Tempest demonstrator in final assembly ahead of planned first flight in 2027
The bulbous central fuselage section of BAE Systems' CAFD demonstrator is seen underway at the firm's facility in Samlesbury, Lancashire, in July 2026. Image: BAE Systems
Tempest demonstrator in final assembly ahead of planned first flight in 2027
BAE Systems' new Tempest prototype, otherwise known as the Combat Air Flying Demonstrator (CAFD), has passed the halfway point in final assembly, with its rollout and first flight remaining on track for 2027.
Britain bets on sovereign AI as defence industry rallies behind national model
Britain bets on sovereign AI as defence industry rallies behind national model
Britain’s leading defence companies have joined forces to develop the UK’s first sovereign frontier AI model, reducing reliance on overseas AI technology.
Defence

5 Aug 2026

SSTL racks up smart storage solution
SSTL racks up smart storage solution
A smart racking solution from Altus has helped Surrey Satellite Technology Limited (SSTL) integrate its materials management processes.
Member News Space

5 Aug 2026

Seraphim Space deploys first capital from £137m C share raise
Seraphim Space deploys first capital from £137m C share raise
The investments have been made in businesses involved in key areas that are driving the next phase of growth within the space sector.
Member News Space

4 Aug 2026

AccelerComm underpins Eclipse Space’s 5G physical layer for satellite constellations
UK From Space-Telecom
AccelerComm underpins Eclipse Space’s 5G physical layer for satellite constellations
Flight-proven 5G non-terrestrial network (NTN) tech from Southampton based AccelerComm, is supporting a scalable direct-to-device and broadband architecture from Starlink veterans behind Eclipse Space.
Member News Space

31 Jul 2026

CAA explores future for BVLOS drone ops
Amazon PrimeAir MK30 drone
CAA explores future for BVLOS drone ops
A new report from the UK Civil Aviation Authority (CAA) outlines a vision for enabling routine Beyond Visual Line of Sight (BVLOS) commercial drone operations alongside existing UK airspace users.
Aerospace Security

3 Aug 2026

UK SMEs given support to commercialise proven solutions
Connected Places Catapult
UK SMEs given support to commercialise proven solutions
A new programme of tailored support is set to help UK small and medium-sized enterprises (SMEs) with proven transport and construction solutions, to commercialise at scale.
Aerospace Security

3 Aug 2026

QinetiQ equips young people with cyber skills
CyberFirst Advanced at Lancaster University
QinetiQ equips young people with cyber skills
Hundreds of youngsters have been given the opportunity to equip themselves with real-world cyber skills.