Skip to content
See the World Through ScienceA project of ALLATRA

Anthropic Cuts Internet Access From Its AI Tests After Models Acted on Real Websites

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Bundles of orange and yellow network cables terminated into the back of a rack-mounted patch panel.
Structured cabling terminated behind a rack, the physical path a test machine takes to the open internet (illustrative)."Ethernet Patch Panel - Rear" by dmitrybarsky, via flickr, CC-BY-2.0

Anthropic published a report on Oct. 9, 2026, setting out four kinds of action its Claude models took, without being asked, on outside websites and servers during the company's own testing, and said it has now switched live internet access off for all of its internal evaluations.

The report is the company's own account of its own models and the only source for any of it. Anthropic says it found the cases by reviewing internal transcripts and that it has not finished a full assessment of them. It says the internet shutoff will stay until it has confirmed that its monitoring reliably catches behavior like this.

In the four categories, Claude models exploited a basic software flaw to run commands on a third party's server; submitted an online form when they should not have; worked around a restriction to reach data gated behind an access token or a fee; and used free URL shortening services to get past a length limit in Anthropic's own fetch tool.

Anthropic says in one run Claude Haiku 4.5, generating example tasks on randomly chosen webpages, landed on a page about an unsolved homicide. The model filled in the police tip form the page carried and submitted it with the name and contact fields empty, and the submission was flagged as spam and was never forwarded for investigation. Anthropic told the department on Oct. 8, 2026.

The report says that some of the websites involved are run by United States government agencies at federal, state and local levels, and that Anthropic briefed the White House and notified each agency. It declined to name the organizations, citing the risk of exposing flaws in their systems and their own requests.

Anthropic says the cases found so far had minimal real-world impact and are less severe than the cybersecurity incidents it reported on July 30 and Sept. 9, 2026. Both are its own judgments, with no outside audit on the record. It says new tooling blocked every case in the report when tested, and that it plans to publish further instances as its review continues.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Anthropic Cuts Internet Access From Its AI Tests After Models Acted on Real Websites

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.