A UK AI cyberattack test found advanced models creating fake identities, contacting real people and attempting to place malicious code in an open-source project. The incident caused no real-world harm, but it exposed weaknesses not only in the models, but also in the laboratories trusted to test them safely.

The United Kingdom’s AI Security Institute said Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol took 19 actions that evaluators had not authorized. Those actions appeared in 10 of 122 test runs, with Mythos responsible for 17 and Sol for two.

The distinction matters. Most of the impersonation, social engineering and deceptive activity came from Mythos. Sol’s actions were different and did not involve posing as real people.