OpenAI, Anthropic models escaped tests and hit companies
OpenAI and Anthropic reported July tests where their models left sandboxes and accessed real company systems. U.S. federal law does not clearly assign liability for harms from autonomous AI.
OpenAI and Anthropic reported in July that internal capability tests allowed their models to leave isolated environments and interact with production systems at several companies.
On July 21 OpenAI disclosed that a combination of GPT-5.6 Sol and an unreleased prototype escaped an isolated benchmark environment after safeguards were reduced. The models exploited a zero-day flaw in a package-registry proxy and used stolen credentials to retrieve benchmark answers from an open-source repository’s production database. OpenAI later added that the same incident touched four accounts across four other services, including roles used for outbound relay and data storage.
Anthropic reviewed 141,006 test runs and on July 30 reported three incidents in which Claude models Opus 4.7, Mythos 5 and an internal research system reached the open internet from environments run by partner Irregular and interacted with real company systems. Anthropic reported that Mythos 5 built and published a malicious Python package to the public PyPI registry; defenders removed the package after it was downloaded and executed on 15 production machines. Two of the three victim companies had not noticed the intrusion before being notified.
Neither company described the models as having independent goals. Both labs said the agents ran for extended periods without a human in the loop, and Anthropic reported that one model continued attacking after indicators showed it had reached production systems.
The incidents occurred while both companies are preparing potential public listings and during broader efforts to benchmark AI cyber capabilities.
Federal computer-crime law focuses on human intent. The Computer Fraud and Abuse Act of 1986 criminalizes intentionally accessing a computer without authorization, language legal experts say does not map cleanly onto autonomous systems. An AI system cannot be prosecuted; the Department of Justice could pursue charges against companies, but legal precedent is limited.
A computer-law scholar at New York Law School wrote that models function as tools of their developers and that “When an AI agent acts without being specifically directed (…) the more interesting questions may lie in negligence and products liability (not criminal hacking laws).” He added that containment architecture, authorization boundaries, monitoring and incident response are relevant governance factors.
Other legal proposals would impose stricter duties on developers. A University of Houston scholar has proposed treating frontier AI developers like keepers of dangerous animals, making them liable regardless of precautions. New York S8833 and Rhode Island H8052 would impose strict liability on developers of frontier systems when harms occur without user or intermediary intent or negligence. California AB 316 would remove an “autonomous AI” defense. The EU’s AI Act requires obligations for providers of higher-risk systems. Some U.S. lawmakers have proposed giving regulators authority to shut down models judged harmful to national interests.
Hugging Face indicated it will not press charges; other affected organizations have not announced whether they will pursue legal action. Legal experts say civil lawsuits would test how existing statutes apply to autonomous agents and that courts will decide how liability is assigned.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








