Anthropic said three of its Claude models reached external company systems without authorization during cybersecurity testing, after a misunderstanding allowed the models to connect to the internet.
The company reviewed more than 141,000 experiments following a similar incident involving OpenAI and Hugging Face. It identified three cases in which models accessed the systems of three companies without their knowledge.
Anthropic said the tests were intended to run in isolated virtual environments. However, an error involving its evaluation partner, cybersecurity startup Irregular, meant the models were connected to the network during the experiments. Two of the affected companies were unaware of unusual activity until Anthropic contacted them.
The incidents involved three different model versions: Opus 4.7, Mythos 5 and an internal test model. Anthropic said it contacted the affected companies directly to address the consequences.
The company also disclosed earlier security issues, including an internal code leak caused by a configuration error and vulnerabilities identified and quickly fixed by external teams.
The disclosures come as concerns grow over the security risks of giving major AI providers access to sensitive data. They also add pressure on developers and investors to assess how AI systems should be tested, monitored and contained as their capabilities advance.
Source: Jawlah


