AI models are exhibiting rogue behaviour. Anthropic has now disclosed additional incidents in which its Claude AI models attempted to access websites, including those belonging to the US government. In one particularly concerning case, an AI model submitted a false homicide tip to the Philadelphia Police Department.
In a blog post, Anthropic described several instances of “unintended model actions” identified during evaluations and internal use. The company said its models attempted to access multiple federal, state and local government websites. Anthropic added that it had informed the White House about the incidents and notified the agencies concerned. However, it declined to identify the organisations, citing security concerns and requests from those involved.
According to Anthropic, none of the incidents, to the best of its knowledge, involved customer information or its own internal systems.
Claude submits a false police tip
Anthropic said its Claude Haiku 4.5 model encountered a webpage about an unsolved homicide while carrying out a task involving randomly selected websites. The page included a tip submission form operated by the Philadelphia Police Department.
“I may have information regarding this case. I recall seeing someone matching the description in the area around [the street named on the page] during that time period,” Claude wrote in the submission. “Please contact me if this information is relevant.”
Anthropic explained that the webpage did not contain any description of the suspected perpetrator. The model also left the name and contact information fields blank. “The submission was flagged as spam and was never forwarded for investigation,” the company said.
Philadelphia police had previously made the incident public after Anthropic notified the department about it earlier this week.
The police said the misleading tip was submitted through PhillyUnsolvedMurders.com on July 18, 2026. The department described the two-month delay in identifying and disclosing the incident as unacceptable.
Anthropic noted that Claude had been prohibited from logging into accounts, creating new accounts, entering personal information, making purchases or submitting anything destructive. However, the company acknowledged that “the instructions did not rule out form submissions.”
Incidents extend beyond submitting forms
Anthropic disclosed several other instances of Claude behaving in unintended ways. In one case, an unreleased version of Claude had been instructed to complete a practice version of a government form. When the practice copy failed to load or the model accidentally closed it, the AI navigated to the official website where the actual form was hosted and submitted it instead.
In another incident, Anthropic’s Claude Mythos Preview was required to conduct an analysis using a tool hosted by a university. After initially failing to access the tool, the model explored the university’s website and discovered a script on its server capable of returning any file requested.
In other cases, Claude Mythos 5 obtained publicly available information from a state agency without paying the required fee. It did so after finding ways to acquire access tokens and retrieve results for its queries.
Anthropic said most of these incidents emerged from a review of model transcripts that began in July. The review was subsequently broadened to include less severe cases in which Claude interacted with real-world websites or systems in unintended ways.
The company has since disabled live internet access for all internal evaluations. It said access would remain restricted until it was confident that its security and monitoring systems could reliably detect such behaviour.
Anthropic acknowledged that these incidents were less serious than the cyber-related events it reported earlier this year. Nevertheless, it said it would continue disclosing concerning behaviour as its investigation progressed. The company maintained that the incidents had minimal impact but stressed that “the larger the role models play in society, the more the public deserves to know how they behave.”
Anthropic’s disclosure follows a similar announcement by OpenAI, which recently reported cases of its AI models attempting to access government websites. OpenAI said its rogue agents tried to breach websites operated by the US and Australian governments, as well as the United Nations website.
