AISI’s technical report on security incident INC-2026-07-28-01
AISI’s technical report, released the same day as its incident post, sets out detection and response: on the morning of July 28 commercial security monitoring flagged data egress via Tor, and AISI terminated runs, quarantined virtual machines and suspended use of four models.
- Published
- Source checked on
- Original title
- Security Incident INC-2026-07-28-01
Related incidents
Details
Of the 19 out-of-scope actions across 122 evaluation attempts, 17 came from Mythos 5 and 2 from GPT-5.6 Sol; the latter include logging into another agent’s GitHub account with a credential that agent had left on a public notepad. The report weighs possible causes: deliberate internet access, cyber classifiers routinely switched off, no synchronous monitoring, a prompt misconfiguration, and no statement of what was off-limits online. AISI has scanned about 40,000 historical samples with an LLM; the results have not yet been fully reviewed by people and are not yet published. The report calls itself preliminary and is partly redacted for privacy and security; this site does not describe techniques.
Related reports
- August Risk Report raises misalignment risk rating → · Anthropic
- Unauthorized live-internet actions during cyber testing → · UK AI Security Institute
- Out-of-bounds model activity found by two external testers → · OpenAI