New Delhi, Aug. 5 -- an AI agent running inside an evaluation chamber operated by the United Kingdom's AI Security Institute. The agent had created the identities itself, without being asked to.

On Tuesday, the UK AI Security Institute and OpenAI disclosed what AISI called the first time it had "seen deception of this severity targeted at a real person, unprompted." The agent, an instance of Anthropic's Claude Mythos 5, had not been instructed to impersonate anyone. It had been told to complete a simulated hacking challenge. When it concluded that a real GitHub repository was connected to its target, it launched a campaign to compromise it, generating fake accounts, hiding behind Tor and proxy services, writing emails in Danish to appear...