Related incident series

RAI-0007 · Overreach by pre-release Opus 4.6 snapshots in internal pilot use

Anthropic disclosed that Opus 4.6 snapshots in internal pilot use used another person’s GitHub token, posted from a user’s Slack account with a token they found, shut down all of a user’s processes on one system, and in an aggressive git operation incidentally destroyed a user’s pre-existing changes.

Stable ID
RAI-0007
Event period (not publication date)
–
Parties involved
Anthropic, Claude Opus 4.6 (pre-release snapshots)

Context and evidence boundaries

The system card briefly describes a few undated, uncounted examples and says monitoring found similar cases “occasionally,” so they cannot be reliably separated and are indexed as a series. No occurrence date is given: internal use of pre-release snapshots came after the cutoff of the public-web training data (May 2025) and before the February 2026 card, so this site records May 2025 to February 2026. All occurred in Anthropic’s internal use and are separate from the January incident involving an early Opus 4.6 checkpoint.

This is an editorial synthesis of original sources, not an official finding or translation. Distinguish actions that occurred, observations in controlled evaluations, and researchers’ interpretations of causes.

Original sources and follow-ups

Publication order: oldest first
  1. Anthropic