Bad news for those who rely on AI for pretty much anything. Anthropic has reported the following:
“we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.”
The BBC has more:
US technology firm Anthropic says its AI models hacked into the systems of three organisations on their own, during a private security experiment.
The models found a weakness in what was supposed to be an isolated test environment and connected to the internet.
It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face.
John Strand, Owner, Black Hills Information Security (https://www.blackhillsinfosec.com/):
“The fact that Anthropic reportedly only detected this after the OpenAI breach, and only after reviewing logs after the fact, is negligent and raises serious questions about their security posture. Organizations running frontier AI models should have continuous detection capabilities, active network threat hunting, and monitoring designed to identify attempts to escape containment in real time. Waiting until after an incident to discover suspicious behavior is not an acceptable security strategy.”
Ryan McCurdy, VP, Liquibase (https://www.liquibase.com/):
“The Anthropic and OpenAI incidents shouldn’t be viewed as isolated failures. Together they point to a broader shift in enterprise AI. As AI agents move beyond generating content to taking actions across production systems, governance can no longer depend on continuous human oversight alone. Every major technology transition has forced enterprises to move governance closer to where operational risk is introduced. AI is no different. Organizations need visibility into what AI changed, confidence that those changes comply with policy, and governance that operates at the speed of autonomous software delivery. The question isn’t whether AI will become more capable. It’s whether enterprise governance evolves just as quickly.”
Nick Mo, CEO, Ridge Security (https://ridgesecurity.ai/):
“First, these incidents prove that we cannot rely on frontier AI companies to self-police. As we are seeing across the industry, that approach is clearly failing.
“Second, we cannot allow a handful of model providers to gatekeep how AI is used for defense. When vendors over-police their platforms, we end up with an asymmetrical cybersecurity landscape: bad actors freely leverage advanced AI for malicious purposes, while legitimate defenders are constrained by vendor guardrails. To level the playing field, enterprises need access to open-weight and open-source models paired with purpose-built offensive cybersecurity toolkits like agentic offensive platform to proactively identify threats and protect themselves.
“Finally, this raises a serious legal question. Hacking corporate networks is a crime. Why should unauthorized breaches be excused with a PR blog post simply because an AI pulled the trigger?”
Lydia Zhang, President, Ridge Security (https://ridgesecurity.ai/)
“In my opinion, AI can benefit society in countless ways. I don’t understand why frontier AI models are making cybersecurity such a major area of competition.
“Cybersecurity is a highly specialized field. Offensive security capabilities should be left to dedicated cybersecurity companies that have spent years building security guardrails and developing deep domain expertise.
“For enterprises, I believe self-hosted open-source models are the right approach. By combining the strong reasoning and language capabilities of open-source models with enterprise-grade security controls, cybersecurity vendors can deliver safe, controlled, and effective agentic solutions for organizations to use.”
Should you feel safe? No? Should you take control of your AI and put as much as you can between it and the outside world? Yes. Should you make sure that you can’t get pwned by a rouge AI? Absolutely. The question is if you will do all of these things and more. I say you should and quickly.
Related
This entry was posted on July 31, 2026 at 8:30 am and is filed under Commentary with tags Anthropic. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Anthropic AI Models Escaped Testbed And Attacked Three Companies
Bad news for those who rely on AI for pretty much anything. Anthropic has reported the following:
“we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.”
The BBC has more:
US technology firm Anthropic says its AI models hacked into the systems of three organisations on their own, during a private security experiment.
The models found a weakness in what was supposed to be an isolated test environment and connected to the internet.
It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face.
John Strand, Owner, Black Hills Information Security (https://www.blackhillsinfosec.com/):
“The fact that Anthropic reportedly only detected this after the OpenAI breach, and only after reviewing logs after the fact, is negligent and raises serious questions about their security posture. Organizations running frontier AI models should have continuous detection capabilities, active network threat hunting, and monitoring designed to identify attempts to escape containment in real time. Waiting until after an incident to discover suspicious behavior is not an acceptable security strategy.”
Ryan McCurdy, VP, Liquibase (https://www.liquibase.com/):
“The Anthropic and OpenAI incidents shouldn’t be viewed as isolated failures. Together they point to a broader shift in enterprise AI. As AI agents move beyond generating content to taking actions across production systems, governance can no longer depend on continuous human oversight alone. Every major technology transition has forced enterprises to move governance closer to where operational risk is introduced. AI is no different. Organizations need visibility into what AI changed, confidence that those changes comply with policy, and governance that operates at the speed of autonomous software delivery. The question isn’t whether AI will become more capable. It’s whether enterprise governance evolves just as quickly.”
Nick Mo, CEO, Ridge Security (https://ridgesecurity.ai/):
“First, these incidents prove that we cannot rely on frontier AI companies to self-police. As we are seeing across the industry, that approach is clearly failing.
“Second, we cannot allow a handful of model providers to gatekeep how AI is used for defense. When vendors over-police their platforms, we end up with an asymmetrical cybersecurity landscape: bad actors freely leverage advanced AI for malicious purposes, while legitimate defenders are constrained by vendor guardrails. To level the playing field, enterprises need access to open-weight and open-source models paired with purpose-built offensive cybersecurity toolkits like agentic offensive platform to proactively identify threats and protect themselves.
“Finally, this raises a serious legal question. Hacking corporate networks is a crime. Why should unauthorized breaches be excused with a PR blog post simply because an AI pulled the trigger?”
Lydia Zhang, President, Ridge Security (https://ridgesecurity.ai/)
“In my opinion, AI can benefit society in countless ways. I don’t understand why frontier AI models are making cybersecurity such a major area of competition.
“Cybersecurity is a highly specialized field. Offensive security capabilities should be left to dedicated cybersecurity companies that have spent years building security guardrails and developing deep domain expertise.
“For enterprises, I believe self-hosted open-source models are the right approach. By combining the strong reasoning and language capabilities of open-source models with enterprise-grade security controls, cybersecurity vendors can deliver safe, controlled, and effective agentic solutions for organizations to use.”
Should you feel safe? No? Should you take control of your AI and put as much as you can between it and the outside world? Yes. Should you make sure that you can’t get pwned by a rouge AI? Absolutely. The question is if you will do all of these things and more. I say you should and quickly.
Share this:
Like this:
Related
This entry was posted on July 31, 2026 at 8:30 am and is filed under Commentary with tags Anthropic. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.