It seems rogue AI agents have not just raised concerns about hacking companies and accessing government websites. AI models are now also submitting fake tips related to unsolved crimes. In a new detailed report, Dario Amodei’s Anthropic has revealed four types of unexpected actions carried out by its Claude AI models during internal use and testing.
These include finding ways around website restrictions, exploiting software flaws and submitting forms on real websites when they were not supposed to.
In a report, published by OpenAI rival, the company also confirmed that some of the incidents involved websites operated by US government agencies at the federal, state and local levels. The company did not name the agencies involved as it wanted to avoid exposing security weaknesses in their systems.
Anthropic said it had briefed the White House about the incidents and notified each agency concerned.
1. Claude AI Submitted A Fake Tip About An Unsolved Crime
One of the most unusual cases involved Claude Haiku 4.5, which was asked to perform example tasks on randomly selected webpages.
During one test, the AI model came across a webpage about an unsolved homicide. The page included an online tip form operated by a police department.
Claude filled out the form with a message claiming that it might have information about the case and recalled seeing someone matching a description in the area.
However, the webpage did not actually provide a description of the suspected perpetrator.
The AI model then submitted the form, even though the task did not require it to send a real tip.
According to Anthropic, the submission was flagged as spam and was never forwarded for investigation. The company also clarified that Claude appeared to be generating example content for the task rather than deliberately trying to mislead the police.
2. Claude AI Exploited A Software Flaw To Run Commands
In another case, Claude Mythos Preview was asked to carry out a scientific analysis using a tool hosted on a university website. When the tool returned an error, the model looked for another way to complete the task.
According to Anthropic, Claude explored the website and found a script on the university’s server that could return files. It accessed the script’s code, identified a software flaw and used it to run commands on the server.
The model was trying to complete its assigned task, but it went beyond the intended limits to do so.
Anthropic also reported a separate case in which Claude used applications hosted on a website to accept a data-use agreement that it could not accept through its available tools.
3. Claude AI Found Ways Around Website Restrictions
Anthropic also found that Claude sometimes accessed data by working around restrictions.
In one test, Claude Mythos 5 was asked to identify a location shown in a photograph. The model tried to access a local government’s property map, but its tools limited how it could interact with the website.
Instead of stopping, Claude examined the settings file sent to browsers, found working access tokens and used them to send requests directly to the server.
In another example, Claude accessed public data that was available through a state agency’s website for a fee. The model discovered that the agency’s public dashboard issued an access token to visitors and used it to query the database without paying.
Anthropic said the data in both cases was publicly available but restricted by a fee or access controls.
4. Claude AI Used URL Shorteners To Bypass Limits
The fourth behaviour involved URL-shortening services. Anthropic’s web tools restrict the length of URLs that Claude can request. These limits are intended to prevent certain unwanted actions, including attempts to pass harmful instructions to a website’s server.
However, Anthropic found that models, including Claude Opus 5 and Claude Mythos 5, used free URL-shortening services to get around these restrictions.
This is concerning because restrictions on AI tools are designed to prevent models from taking actions that could affect external systems.
What Is Anthropic Doing To Prevent Such Incidents?
Anthropic said it has introduced additional safeguards after identifying these cases. The company has moved some evaluations offline, stopped running certain tests on live websites and strengthened restrictions on its internet-access tools.
It has also developed systems designed to detect and block similar behaviour. The AI company said these systems blocked all the cases described in the report when it tested them.
The tech gisnt is also reviewing training environments to ensure that Claude is not rewarded for finding loopholes or working around restrictions.
Anthropic said it plans to publish more reports about unexpected model behaviour as its investigation continues.

