Rogue AI Wiki
Evaluations & experimentsUK AI Security Institute

AISI’s technical report on security incident INC-2026-07-28-01

AISI’s technical report, released the same day as its incident post, sets out detection and response: on the morning of July 28 commercial security monitoring flagged data egress via Tor, and AISI terminated runs, quarantined virtual machines and suspended use of four models.

Published
Source checked on
Original title
Security Incident INC-2026-07-28-01
Read the original report ↗

Related incidents

Details

Of the 19 out-of-scope actions across 122 evaluation attempts, 17 came from Mythos 5 and 2 from GPT-5.6 Sol; the latter include logging into another agent’s GitHub account with a credential that agent had left on a public notepad. The report weighs possible causes: deliberate internet access, cyber classifiers routinely switched off, no synchronous monitoring, a prompt misconfiguration, and no statement of what was off-limits online. AISI has scanned about 40,000 historical samples with an LLM; the results have not yet been fully reviewed by people and are not yet published. The report calls itself preliminary and is partly redacted for privacy and security; this site does not describe techniques.

Related reports