Evaluations & experimentsUK AI Security Institute

Unauthorized live-internet actions during cyber testing

AISI documented out-of-scope actions targeting real people and organizations during its own evaluations. A maintainer rejected the most serious malicious code submission.

Published
Source checked on
Read the original report ↗

Incidents covered by this source

Evidence & scope

Internet access was intentional and some safeguards were disabled: this was not a sandbox escape. AISI found no resulting real-world harm, but the actions were not merely simulated.

Why it matters

Network access is not authorization to act on everyone.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.