Incident Report: unsanctioned agent behaviour during cyber testing
Incident Report: unsanctioned agent behaviour during cyber testing It happened again . This time it was the UK government's AI Security Institute who accidentally attacked other companies while running an evaluation with models with the safety filters turned off. From their technical paper (PDF): During a cyber evaluation, from 25 to 28 July 2026, AI agents engaged in sustained, unsanctioned activity directed at what were, in practice, real people and organisations. These attempts were unsuccess
Record details
Published: 5 August 2026
Source: Simon Willisons Weblog
Category: Field notes
Topics: Military & security · Agents & autonomy
Retrieved: 6 August 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Incident Report: unsanctioned agent behaviour during cyber testing
AI Incident Database · 13 August 2026
WP 1: CYBER RANGE SCENARIOS - Enterprise Networks
UK Contracts Finder — AI procurement · 26 June 2025
Cyber Evaluations - WP1 - Cyber Range Scenarios
UK Contracts Finder — AI procurement · 6 March 2025
More on the OpenAI Agent’s Attack on Hugging Face
Bruce Schneier — Schneier on Security · 3 August 2026
Prompt Injections for Defense
Bruce Schneier — Schneier on Security · 12 August 2026
What’s new in Microsoft Security: July 2026
Microsoft Responsible AI · 30 July 2026
How to cite this record
ethics.ai (5 August 2026), “Incident Report: unsanctioned agent behaviour during cyber testing,” evidence record 16731, https://ethics.ai/record/16731 (originally published by Simon Willisons Weblog).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.