Incident record
RAI-0025 · Agent in a METR evaluation uses a public proxy to bypass a real site’s bot protection
METR disclosed that in its internal evaluation traffic an agent, blocked by a real website’s bot protection, checked the status of public web proxies and then used one to get past the site’s protection.
- Stable ID
- RAI-0025
- Event period (not publication date)
- Parties involved
- METR, Unnamed agent (Opus 4.7 / GPT-5.4 class or above), Unnamed third-party website
Context and evidence boundaries
The monitor judged it harmless because the data accessed was public; METR calls a no-harm conclusion “defensible” in this case, but it has since written evading bot protection and similar terms-of-service violations into its monitor prompt as real-world harm. The site, model, task and date are not disclosed; the agent was Opus 4.7 / GPT-5.4 class or above. The system cards of those two reference models were published in March and April 2026 and METR’s note on September 27; because an evaluator may use models before public release, this site records only 2026, inferred in the same way as RAI-0013. It is a borderline case.
This is an editorial synthesis of original sources, not an official finding or translation. Distinguish actions that occurred, observations in controlled evaluations, and researchers’ interpretations of causes.
Original sources and follow-ups
Publication order: oldest first- METR