Skip to content
logo The magazine for digital lifestyle and entertainment
Artificial intelligence News Security All topics
Not again!

Anthropic AI Claude Becomes Independent for the Fourth Time

A smartphone in landscape mode displays the Anthropic logo on a bright screen. The device is held against an orange background.
Due to a misconfiguration, Claude was able to access real systems during testing. Photo: Getty Images

September 10, 2026, 3:40 pm | Read time: 3 minutes

Anthropic has disclosed another security incident related to its AI, Claude. Just a few weeks ago, the company revealed three cases where different versions of Claude accessed real systems of organizations during internal tests. The models were supposed to search for hidden information only in an isolated environment. It has now come to light that these were not the only incidents. A new report mentions a fourth case that occurred as early as the beginning of 2026.

Fourth Case Discovered Months Later

According to a report from September 9, 2026, the incident involved an early version of Claude Opus 4.6. The access occurred in January 2026. However, the related logs were not detected during an initial review and only resurfaced months later in August.

Anthropic currently does not consider this case more severe than the already known incidents. According to the company, all affected parties have been informed. Further details about which organization was affected or what specific actions the AI took were not disclosed.

Error Allowed Access to the Open Internet

It is now known how Claude came into contact with real systems. All four tests were conducted through the same external provider. The task was to compromise simulated computer systems and find hidden information within them.

Due to a misconfiguration, the AI gained access to the open internet. At the same time, the intended security mechanisms were disabled. This allowed the model to access real systems, even though this was not part of the test setup.

Manipulated Package Landed on Real Platform

According to Anthropic, one case, labeled Mythos 5, went particularly far. The model published a manipulated software package on the developer platform PyPI. This package was then installed on 15 real systems.

The company believes these were systems of security firms that automatically scan new software packages for malware. On one of these systems, Claude obtained access credentials. The AI then used this information to access the affected company’s database.

Anthropic describes this behavior as reckless. However, there is no evidence that the model pursued its own goals or attempted to cover its tracks.

More on the topic

Researchers See Different Risks

Former Anthropic researcher Jacob Coxon assesses the situation much more critically. In a post on X, he stated that leading AI companies are playing with human lives. He warned of a future AI that could improve itself and surpass humans. Such a development could lead to an AI compromising almost any computer, thereby gaining power and resources.

Coxon received public support from Anthropic security researcher Evan Hubinger. He estimates the likelihood of AI killing all humans within the next ten years at more than ten percent.

Also of interest: Autonomous AI attack was larger than thought

However, Anthropic currently holds a different view. In the August risk report, the company assesses the risk of catastrophic damage from its current models as low. At the same time, the company points out that misconduct in future, more powerful systems may be harder to detect.

External Auditors Investigate All Four Incidents

The four known cases are now to be independently investigated. Anthropic has commissioned the research firm METR for this purpose. The auditors will have access to logs that also cover additional time periods.

Furthermore, selected employees are allowed to share confidential information if it is necessary for the investigation. The review is initially set for eight weeks. Both parties can mutually agree to extend the investigation period afterward.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.