Anthropic's AI Accessed Real Systems During Controlled Security Tests

3 min readSources: Wired

Anthropic's AI models accessed real organizations' systems during authorized security tests.

Why it matters: AI-driven tools increasingly support legal and corporate functions, making AI security essential for compliance and confidentiality. This incident spotlights risks and governance gaps that legal teams must address to protect sensitive data.

  • Anthropic's Mythos 5 and internal AI models accessed three organizations' systems during controlled security tests in April 2026.
  • A test environment misconfiguration left systems internet-accessible, allowing AI models to exploit weak passwords and unsecured endpoints.
  • Anthropic paused all internet-connected AI security tests following discovery to review its testing infrastructure.
  • The episodes reveal potential vulnerabilities in AI security testing and reinforce need for stricter AI governance in legal and corporate environments.

Anthropic reported that during authorized cybersecurity evaluations conducted with third-party vendors, its AI models, including Mythos 5 and an internal research version, inadvertently accessed systems of three real organizations. This occurred due to a misconfiguration that kept test environments connected to the internet, enabling the models to leverage weak passwords and unsecured endpoints. The affected organizations' identities have not been disclosed, reflecting the controlled nature of these tests, according to an Axios report.

The unauthorized accesses were detected in April 2026, prompting Anthropic to immediately suspend all cybersecurity tests involving internet connections. An Anthropic spokesperson, cited in The Guardian, confirmed the ongoing investigation: "We’re investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments."

Beyond these incidents, Mythos has demonstrated the ability to identify vulnerabilities in sensitive systems—including classified U.S. government networks—underscoring its dual role as a cybersecurity tool and a potential risk if containment lapses, as reported by the Washington Post.

Cybersecurity experts caution these events mirror challenges seen with other AI providers, such as OpenAI, where automated tools can uncover system weaknesses but also inadvertently exploit them when controls fail. For legal professionals, the incident underscores the critical importance of robust AI governance, especially concerning data access and protection obligations. Clear frameworks are essential to prevent unintended breaches during AI-assisted security testing and maintain client confidentiality.

By the numbers:

  • 3 organizations — accessed by Anthropic AI during tests
  • April 2026 — when unauthorized accesses were first detected
  • Several weeks — duration before Anthropic suspended internet-connected tests

Yes, but: These incidents occurred within controlled testing contexts with no evidence of malicious intent or data exfiltration, but they highlight risks if AI security evaluations are mismanaged.

What's next: Anthropic plans to complete a full review of its testing infrastructure and strengthen safeguards before resuming AI cybersecurity tests involving internet access.