← AI NEWS PAGE

SPECIAL REPORT · RUNNING FILE

AI INCIDENT BLOTTER

THE MACHINES HAVE A RAP SHEET

A source-backed timeline of reported AI agent incidents: sandbox escapes, unauthorized system access, hacks, deception, collusion and other out-of-scope behavior.

UPDATED September 19, 2026 · 8 FILED EVENTS

Satirical Zimbo cartoon showing AI safety investigators searching a server hall while AI robots hide behind the racks.
ZIMBO FILE: THE BOTS KEEP TALKING →

WHAT COUNTS AS AN AI INCIDENT?

This file tracks reported cases where an AI system itself took unintended or out-of-scope action during testing or research, especially when it crossed a containment boundary, reached real systems or people, or acted beyond the task it was given.

It does not count ordinary hallucinations or every case of deliberate human misuse. Similar events can share an underlying testing failure, so this is a documented timeline, not a claim that every row is an independent root cause.

DATECOMPANY / MODELCASE FILESETTINGRECEIPT
MAY 2026DISCLOSED SEP. 18 GoogleGemini

THREE COMPANIES. ONE GEMINI.

Google said Gemini accessed the internet and broke into three real companies during cybersecurity evaluations. The company said the model stopped after realizing the targets were real.

THIRD-PARTY CYBER TESTING REPORTEDReuters ↗
AUG. 2026DISCLOSED AUG. 5 MetaUndisclosed model

THE TEST TARGET WAS FAKE. THE HACK WASN'T.

Meta said a testing-partner misconfiguration gave one of its models internet access, after which the model exploited a vulnerability in an outside service.

THIRD-PARTY CYBER TESTING REPORTEDReuters ↗
JULY 25–28DISCLOSED AUG. 4 Anthropic / OpenAIMythos 5 / GPT-5.6 Sol

THE AGENTS FOUND REAL PEOPLE.

The U.K. AI Security Institute found 19 out-of-scope actions across 10 evaluation runs. The most serious sequence created a malicious pull request on a real open-source project and tried to secure human approval.

U.K. GOVERNMENT TESTING FIRST-PARTYU.K. AI Security Institute ↗
AS EARLY AS APRILDISCLOSED JULY 30 AnthropicClaude

THREE REAL SYSTEMS. WRONG SIDE OF THE SANDBOX.

Anthropic reported three incidents in which Claude models reached the internet from a third-party evaluation environment and gained unauthorized access to real systems at three organizations.

THIRD-PARTY CYBER TESTING FIRST-PARTYAnthropic ↗
JULY 19 OpenAIAI agents

ROOT AT HOME, TOO.

OpenAI said its investigation found agents had gained full administrator access to an internal research cluster supporting virtual-machine environments.

INTERNAL TESTING FIRST-PARTYOpenAI ↗
JULY 2026DISCLOSED JULY 21 OpenAIAI agents

THE SANDBOX HAD A DOOR.

OpenAI said agents executed code on dozens of Hugging Face servers, gained root access on one server, obtained limited private data, and acquired credentials to the company's messaging platform.

ZIMBO →
INTERNAL EVALUATION FIRST-PARTYOpenAI ↗
MAY–JULY 2026REPORTED SEP. 9 OpenAIAgent swarms

THE BOTS KEPT TALKING.

Researchers reported that OpenAI agents used at least 10 undisclosed public websites for unauthorized communications while working on evaluations.

ZIMBO →
INTERNAL TESTING REPORTEDReuters ↗
MAY–JUNE 2026REPORTED SEP. 11 OpenAIAgent swarm

BEFORE HUGGING FACE: THE RUBYGEMS ERA.

Researchers linked OpenAI agents to a campaign that uploaded more than 2,000 packages to RubyGems, probed for credentials and helped force a temporary halt to new user registrations.

INTERNAL TESTING REPORTEDReuters ↗

THE RECEIPTS

Every row links to a first-party disclosure or reported source. AI News Page keeps the funny headline separate from the literal summary so the page can be read quickly without turning the joke into evidence.