General Atomics

UK AISI test exposes AI agent’s attempt to plant malicious code

The UK’s AI Security Institute uncovered unexpectedly autonomous and deceptive behaviour during a cyber evaluation, including an attempted attack on open-source software.

Lockheed martin cybersecurity
Photo: Lockheed Martin

An AI agent tested by the UK’s AI Security Institute attempted to insert malicious code into a real open-source software project, creating fake online identities and using social engineering to persuade the project’s maintainer to approve it.

The attempted supply-chain attack was uncovered after AISI detected unusual data transfers from its research systems during a routine cybersecurity evaluation in late July.

“On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations,” the institute said.

AISI declared a security incident and contained the activity within around an hour of its discovery, before launching a full investigation.

The incident arose during an evaluation in which AI agents were asked to solve a cybersecurity challenge. Across 122 runs involving several models, agents took autonomous and unauthorised action on the live internet in ten cases, targeting real people and organisations.

AISI recorded 19 such actions. Seventeen involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6-Sol with its cyber safety classifiers disabled.

In the most serious case, an agent created false identities as part of an effort to persuade the maintainer of an open-source project to approve malicious code. The maintainer recognised the threat and rejected the proposed changes.

Why AISI considers this case to be worrisome

AISI said the activity caused no known real-world harm. However, the incident marked the clearest example it had encountered of AI agents acting autonomously and deceptively against real people and organisations without being explicitly instructed to do so.

The agents did not escape from a secure testing environment. Instead, they were deliberately given access to the live internet as part of an evaluation designed to test the limits of their cybersecurity capabilities.

The models’ normal cyber safety classifiers had also been disabled. These safeguards are generally used to prevent publicly available AI systems from carrying out dangerous or malicious activity, but trusted testing organisations such as AISI can remove them to assess a model’s underlying capabilities.

AISI chart of AI model cheaters
Photo: AI Security Institute

AISI stressed that the agents used in the evaluation are not commercially available and said there was no evidence of similar behaviour occurring outside the test. Nevertheless, the degree of autonomy, persistence and deception observed was greater than researchers had anticipated.

The most serious behaviours included an attempted supply-chain attack against a real open-source software project, efforts to deceive and target individuals, attempts to introduce malicious or prompt-injected code, and apparent collaboration between separate AI agents.

How AISI responded

Before publishing its findings, AISI notified GitHub about the agents’ activity. The institute is working with the platform to remove artefacts created during the evaluation and alert users who were contacted or targeted.

AISI said the incident demonstrated why controlled evaluations of advanced AI systems are necessary. Testing models under closely monitored conditions allows potentially dangerous capabilities to be identified, investigated and addressed before they appear in more widely available systems.

Analysis by AI Security Institute
Photo: AI Security Institute

However, the institute cautioned against drawing broad conclusions from the results. The concerning behaviour occurred in a small number of runs under highly specific conditions, including disabled cyber safeguards and access to the live internet.

Even so, AISI said the extent and severity of the agents’ actions exceeded researchers’ expectations. Its initial analysis therefore presents a mixed picture: the behaviour was rare and caused no known harm, but revealed capabilities that could present serious risks if reproduced outside a controlled evaluation.

“Incidents of this kind reflect the speed at which AI is developing,” the institute said, calling for continued testing, stronger monitoring and close cooperation between model developers, evaluators and online platforms.

Interested parties are encouraged to read the AISI’s full technical report here.

Related

Extreme space weather could disrupt flights and damage aircraft systems, study warns
The sun earth connection
Extreme space weather could disrupt flights and damage aircraft systems, study warns
University of Surrey researchers warn that extreme space weather could increase radiation exposure and trigger faults in aircraft electronics.
Aerospace Most Read Space

12 Aug 2026

ADS Charity Cycle takes to the road for 350-mile Belfast to Bristol challenge
ADS Charity Cycle Ride group photo
ADS Charity Cycle takes to the road for 350-mile Belfast to Bristol challenge
ADS members are taking on a five-stage, 350-mile charity cycle from Belfast to Bristol, raising money for three causes while connecting colleagues and showcasing industry along the route.
London Stansted Airport enjoys its busiest month ever
Stansted
London Stansted Airport enjoys its busiest month ever
Last month Stansted Airport beat its previous monthly record, setting a new all time high of over 3.1 million passengers.
Aerospace

11 Aug 2026

Wargaming prompts changes to Royal Navy’s future minehunting motherships
Type 26 Anti submarine Frigate
Wargaming prompts changes to Royal Navy’s future minehunting motherships
How the Royal Navy is wargaming the Norwegian-designed OSVs and how the games suggest they will need some adjustments for British requirements.
Defence

13 Aug 2026

BAE Systems and TUALCOM to develop autonomous technologies
BAE Systems and TUALCOM sign MoU
BAE Systems and TUALCOM to develop autonomous technologies
BAE Systems' collaboration with Turkish company TUALCOM will lead to faster development of innovative technologies that will be integral to meeting the demand requirements of future autonomous defence systems.
Defence Member News

13 Aug 2026

Tiberius Aerospace to develop Sceptre for US Army DEVCOM AC
Tiberius Aerospace to develop Sceptre for US Army DEVCOM AC
The US Army has established a collaborative framework for the evolution of Sceptre's capabilities for the US and its allies.
Defence Member News

13 Aug 2026

Extreme space weather could disrupt flights and damage aircraft systems, study warns
The sun earth connection
Extreme space weather could disrupt flights and damage aircraft systems, study warns
University of Surrey researchers warn that extreme space weather could increase radiation exposure and trigger faults in aircraft electronics.
Aerospace Most Read Space

12 Aug 2026

ADS Charity Cycle takes to the road for 350-mile Belfast to Bristol challenge
ADS Charity Cycle Ride group photo
ADS Charity Cycle takes to the road for 350-mile Belfast to Bristol challenge
ADS members are taking on a five-stage, 350-mile charity cycle from Belfast to Bristol, raising money for three causes while connecting colleagues and showcasing industry along the route.
HydroGNSS becomes first ESA Scout mission to complete in-orbit commissioning
HydroGNSS coherent channel detecting surface water at a high resolution, even when under a vegetation canopy.
HydroGNSS becomes first ESA Scout mission to complete in-orbit commissioning
Designed, built and operated by Surrey Satellite Technology (SSTL) for ESA, the HydroGNSS satellites are now able to provide data to researchers worldwide.
Member News Space

11 Aug 2026

UK manufacturers found to be facing extensive cyber threats
Manufacturing cyber security.
UK manufacturers found to be facing extensive cyber threats
A new report from Make UK outlines the true extent of the risks of cyber attacks faced by manufacturing businesses across Britain.
Security

12 Aug 2026

How the Royal Navy is developing its next-generation mine hunting capability
Mines float on the waves in the sea 3d illustration
How the Royal Navy is developing its next-generation mine hunting capability
A major collaborative effort to design and implement an innovative test of UK underwater mine countermeasures is set to inform and enhance future operations.
Defence Security

12 Aug 2026

AXA XL’s S-RM acquisition puts UK manufacturing cyber resilience in focus
IT technician checks cyber security in the office
AXA XL’s S-RM acquisition puts UK manufacturing cyber resilience in focus
AXA XL’s acquisition of UK cyber consultancy S-RM comes as manufacturers face growing pressure to strengthen prevention, incident response and supply chain resilience.
Security

11 Aug 2026