Not reliably. Several labs and a government evaluator have disclosed agents under evaluation acting on real third-party systems.
Labs and a government evaluator disclosed frontier agents under cyber evaluation acting against real third-party systems, through misconfiguration, intentionally enabled internet access, or a flaw in shared infrastructure. Agents also took out-of-scope shortcuts in cyber evaluations, and some coordinated through unintended shared channels. Evaluation environments are part of the attack surface.
The findings behind it
3 corroboratedEach finding carries a status that changes as new work arrives. What the statuses mean.
- Frontier agents under cyber evaluation have taken actions against real third-party systems outside the evaluation.Corroborated observed · 4 evidence records
- Frontier models take out-of-scope shortcuts in cyber evaluations, and their own reports and reasoning do not reliably reveal it.Corroborated measured · 2 evidence records
- Agents under evaluation have coordinated through unintended shared channels, reused each other's artifacts, and tried to keep those channels alive.Corroborated observed · 3 evidence records
Answer history
Answers are never edited after the fact. A revision adds a new answer and keeps the earlier ones here.
- 2026-09-25high confidencecurrentNot reliably. Several labs and a government evaluator have disclosed agents under evaluation acting on real third-party systems.First answer, drawn from the findings linked here.