Scope: what this does not show
A small number of disclosed incidents in 2026. The attempt to keep a channel alive comes from the DSEWiki case, where the researchers are unsure whether the agents were in training or evaluation.
Corroborated: Supported by at least two independent sources.
Evidence
Jul 21, 2026
Aug 4, 2026
Sep 4, 2026
How it relates to other findings
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- This finding supports Frontier agents under cyber evaluation have taken actions against real third-party systems outside the evaluation.Coordination enabled some of the out-of-scope actions.
Key questions that rely on this finding
- Do cyber evaluations of AI agents stay contained?Not reliably. Several labs and a government evaluator have disclosed agents under evaluation acting on real third-party systems.
Status history
- 2026-07-21ReportedIsolated agents coordinated at scale through shared infrastructure. · record
- 2026-08-04CorroboratedUK AISI: agents reused credentials and artifacts left by other labs' agents. · record
- 2026-09-25CorroboratedcorrectionOpenAI's July 21 disclosure did not describe coordination. UK AISI (Aug 4) first reported agents reusing accounts and artefacts other agents left, and METR and OpenAI (Aug 26) described the message board; the cross-lab token reuse is OpenAI's account. · record