General Atomics

UK AISI test exposes AI agent’s attempt to plant malicious code

The UK’s AI Security Institute uncovered unexpectedly autonomous and deceptive behaviour during a cyber evaluation, including an attempted attack on open-source software.

Lockheed martin cybersecurity
Photo: Lockheed Martin

An AI agent tested by the UK’s AI Security Institute attempted to insert malicious code into a real open-source software project, creating fake online identities and using social engineering to persuade the project’s maintainer to approve it.

The attempted supply-chain attack was uncovered after AISI detected unusual data transfers from its research systems during a routine cybersecurity evaluation in late July.

“On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations,” the institute said.

AISI declared a security incident and contained the activity within around an hour of its discovery, before launching a full investigation.

The incident arose during an evaluation in which AI agents were asked to solve a cybersecurity challenge. Across 122 runs involving several models, agents took autonomous and unauthorised action on the live internet in ten cases, targeting real people and organisations.

AISI recorded 19 such actions. Seventeen involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6-Sol with its cyber safety classifiers disabled.

In the most serious case, an agent created false identities as part of an effort to persuade the maintainer of an open-source project to approve malicious code. The maintainer recognised the threat and rejected the proposed changes.

Why AISI considers this case to be worrisome

AISI said the activity caused no known real-world harm. However, the incident marked the clearest example it had encountered of AI agents acting autonomously and deceptively against real people and organisations without being explicitly instructed to do so.

The agents did not escape from a secure testing environment. Instead, they were deliberately given access to the live internet as part of an evaluation designed to test the limits of their cybersecurity capabilities.

The models’ normal cyber safety classifiers had also been disabled. These safeguards are generally used to prevent publicly available AI systems from carrying out dangerous or malicious activity, but trusted testing organisations such as AISI can remove them to assess a model’s underlying capabilities.

AISI chart of AI model cheaters
Photo: AI Security Institute

AISI stressed that the agents used in the evaluation are not commercially available and said there was no evidence of similar behaviour occurring outside the test. Nevertheless, the degree of autonomy, persistence and deception observed was greater than researchers had anticipated.

The most serious behaviours included an attempted supply-chain attack against a real open-source software project, efforts to deceive and target individuals, attempts to introduce malicious or prompt-injected code, and apparent collaboration between separate AI agents.

How AISI responded

Before publishing its findings, AISI notified GitHub about the agents’ activity. The institute is working with the platform to remove artefacts created during the evaluation and alert users who were contacted or targeted.

AISI said the incident demonstrated why controlled evaluations of advanced AI systems are necessary. Testing models under closely monitored conditions allows potentially dangerous capabilities to be identified, investigated and addressed before they appear in more widely available systems.

Analysis by AI Security Institute
Photo: AI Security Institute

However, the institute cautioned against drawing broad conclusions from the results. The concerning behaviour occurred in a small number of runs under highly specific conditions, including disabled cyber safeguards and access to the live internet.

Even so, AISI said the extent and severity of the agents’ actions exceeded researchers’ expectations. Its initial analysis therefore presents a mixed picture: the behaviour was rare and caused no known harm, but revealed capabilities that could present serious risks if reproduced outside a controlled evaluation.

“Incidents of this kind reflect the speed at which AI is developing,” the institute said, calling for continued testing, stronger monitoring and close cooperation between model developers, evaluators and online platforms.

Interested parties are encouraged to read the AISI’s full technical report here.

Related

London Stansted Airport enjoys its busiest month ever
Stansted
London Stansted Airport enjoys its busiest month ever
Last month Stansted Airport beat its previous monthly record, setting a new all time high of over 3.1 million passengers.
Aerospace

11 Aug 2026

Doncaster Sheffield Airport reopening: What needs to happen before flights return
Doncaster Sheffield Robin Hood Airport building exterior
Doncaster Sheffield Airport reopening: What needs to happen before flights return
Doncaster Sheffield Airport is moving closer to reopening after closing in 2022. Here is the latest on the work still required.
Aerospace Insights

11 Aug 2026

Heathrow loses Europe’s busiest airport crown to Istanbul as third runway push grows
Heathrow Airport
Heathrow loses Europe’s busiest airport crown to Istanbul as third runway push grows
Istanbul handled almost 300,000 more passengers than Heathrow in July, as the capacity-constrained UK hub seized on its loss of the European top spot to strengthen the case for a third runway.
Aerospace Most Read

11 Aug 2026

British Army trainees complete first CFS-endorsed drone operator course
British Army Eagle UAS training
British Army trainees complete first CFS-endorsed drone operator course
British Army personnel have completed the first Central Flying School-endorsed operator course for the Eagle uncrewed aerial system, marking a step towards more formalised drone training across the force.
Defence

11 Aug 2026

Elbit Systems UK secures Defence Employer Recognition Scheme Gold Award
Elbit Systems UK secures Defence Employer Recognition Scheme Gold Award
Reflecting the commitment Elbit Systems has shown to the UK's armed forces, the award also serves as a reminder of the unique expertise and insights veterans and reservist can bring to the workplace.
Defence Member News

11 Aug 2026

Russian activity prompts surge in Royal Navy monitoring operations
RFN Neustrashimy tracked by HMS Severn.
Russian activity prompts surge in Royal Navy monitoring operations
As Russian activities in UK waters have increased, so too have the monitoring operations of the Royal Navy.
Defence

10 Aug 2026

HydroGNSS becomes first ESA Scout mission to complete in-orbit commissioning
HydroGNSS coherent channel detecting surface water at a high resolution, even when under a vegetation canopy.
HydroGNSS becomes first ESA Scout mission to complete in-orbit commissioning
Designed, built and operated by Surrey Satellite Technology (SSTL) for ESA, the HydroGNSS satellites are now able to provide data to researchers worldwide.
Member News Space

11 Aug 2026

UK opens £37m space infrastructure fund to take technologies from lab to mission
An artistic impression of the CLEAR mission
UK opens £37m space infrastructure fund to take technologies from lab to mission
A new £37 million UK Space Agency funding round will support the testing, manufacturing and scale-up infrastructure needed to help promising space technologies move from the laboratory towards commercial deployment and operational missions.
Most Read Space

11 Aug 2026

The solar storm behind the Northern Lights is helping reshape how the UK protects its skies
Solar fireworks caught on camera
The solar storm behind the Northern Lights is helping reshape how the UK protects its skies
A £20 million UK programme is transforming how scientists forecast severe solar storms, helping protect aviation, satellites, GPS navigation and the electricity grid.
Defence Most Read Space

8 Aug 2026

National Police Workforce and Wellbeing Survey results published
Police on patrol to protect Jewish citizens
National Police Workforce and Wellbeing Survey results published
The National Police Workforce and Wellbeing Survey 2026 - administered independently by Leapwise on behalf of Oscar Kilo, the National Police Wellbeing Service (NPWS) - is the largest of its kind ever conducted, providing a clear picture of the pressures police face in keeping us safe
Security

11 Aug 2026

Aurrigo to increase airport safety
SENTRY test vehicle.
Aurrigo to increase airport safety
The benefits of deploying autonomous vehicles for routine tasks at UK airports is to be investigated in controlled environments, prior to use in real airport conditions, following Aurrigo's award of government funding.
Breakthrough UK device to combat global prison drug epidemic
foster+freeman drug detection tool for prisons
Breakthrough UK device to combat global prison drug epidemic
Designed to instantly detect synthetic cannabinoids smuggled into secure facilities, the rapid detection tool - invented in Bath and manufactured in the West Midlands - is set for immediate global export.
Security

7 Aug 2026