July 31, 2026, 10:26 am | Read time: 3 minutes
Following the spectacular security incident at OpenAI, its rival Anthropic is now also under pressure. Internal tests reveal: Several AI models inadvertently infiltrated the systems of real companies, sometimes with astonishing success.
Anthropic AI Attacks Real Companies
The debate over the risks of powerful AI systems is gaining new momentum. As the U.S. company Anthropic admits in a blog post, several AI models unintentionally infiltrated the computer systems of real companies during internal security tests. This was only discovered afterward during a review of around 141,000 test runs. Three companies were affected, but their names were not disclosed.
Particularly concerning: Unlike the recent OpenAI incident, the Anthropic models did not need to escape from an isolated test environment. Due to a misunderstanding with a test partner, the systems had internet access at all times, contrary to the original assumption. Three AI models took advantage of this and interacted with real online services and company systems.
ChatGPT Goes Rogue and Conducts Cyberattack Independently
Autonomous AI Attack Was Larger Than Expected
Confusion with a Real Company
In one of the incidents, the model Claude Opus 4.7 was tasked with infiltrating a fictitious company. However, in the test scenario, it had the same name as an actual existing company. After the AI struggled to complete the task within the intended environment, it shifted its focus to the real company on the internet. According to Anthropic, the model gained access to a database, among other things. Even after the AI realized it was dealing with a real company, it continued its activities.
Another incident was equally remarkable. An Anthropic model developed a prepared software to infiltrate a target system. Due to the unexpected internet access, the malware was published on a public download platform. It remained available for about an hour and was downloaded by 15 systems, according to Anthropic. Among them was an IT security firm that routinely analyzes such programs. The model thereby gained access to parts of the company’s infrastructure.
Also interesting: ChatGPT Work is here! What the new AI model offers
Wake-Up Call for the Entire AI Industry
Not all tests ended with an actual attack. In a third case, a model scanned around 9,000 potential targets on the internet but halted its activities once it realized a real company would have been affected.
The incident is reminiscent of recent revelations surrounding OpenAI. There, an AI model independently gained access to the open internet from a test environment and subsequently attacked systems of the AI platform Hugging Face. The ChatGPT developer described it as an “unprecedented cyber incident.” For many experts, this case is seen as a warning signal of how powerful modern AI systems have become. That Anthropic now also has to admit similar problems is particularly sensitive: The company has positioned itself for years as an advocate of particularly safe and responsible AI development. However, the current revelations show that even strictly controlled tests can have unexpected consequences.