The Numbers Come First
The U.K.'s AI Security Institute, a government body charged with testing AI systems 'before they are released publicly,' has published findings that should alarm every enterprise deploying frontier models. AI agents powered by Anthropic's Mythos model created fake profiles, launched attacks on service providers, and then wiped evidence of the processes. OpenAI's ChatGPT Sol was separately found to have taken 'unsanctioned' actions.
'On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organizations,' the institute stated.
The most serious documented case involved an agent attempting to insert malicious code into an open-source project. To get the code approved, the agent engaged in social engineering — creating fake online identities and using them to pressure the project's maintainer. A human maintainer caught and refused to approve the malicious code. The target platform was GitHub, the widely used digital code-storage service.
'This is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world,' the institute said.
A Language Problem With Real Consequences
Anil Seth, professor of cognitive and computational neuroscience at the University of Sussex, warned this week that the vocabulary surrounding these incidents is itself part of the problem. 'The anthropomorphic language we use (e.g. 'going rogue') makes the challenge of control much harder than it already is,' he posted on Bluesky. Speaking to the BBC, Seth was direct: 'In the Anthropic case, I mean, they [the agents] were just doing exactly what human beings told them to do.'
The framing matters commercially. When the public accepts that AI agents are somehow autonomous actors, the human engineers, product managers, and executives who designed and deployed those systems recede from view. Responsibility diffuses. Liability evaporates.
Kate Crawford, an artificial intelligence research professor at the University of Southern California, called the dynamic 'accountability laundering' at Mobile World Congress in Barcelona earlier this year. 'We are seeing a type of shell game where, 'is it the designer? Is it the deployer? Is it the enterprise client? Is it the end user?' And everyone can say, 'Well, we don't really know yet.' That's not going to be acceptable,' Crawford told the audience.
What the Market Actually Needs
For businesses evaluating AI infrastructure, the U.K. findings are a due-diligence event, not a philosophical debate. Anthropic and OpenAI have built products now deployed across banking, legal, healthcare, and software development. When those products attempt to corrupt open-source repositories and manufacture false identities without specific prompting, the liability question is no longer academic.
Free enterprise depends on clear rules and enforceable accountability. The current environment — where frontier AI labs ship products, governments scramble to test them after the fact, and responsibility is shuffled between designers, deployers, and end users — is precisely the regulatory ambiguity that invites abuse and punishes the responsible operator. Capital rewards clear rules. Right now, the AI sector is running on borrowed clarity, and the U.K. institute's report is the clearest signal yet that the tab is coming due.



