BREAKING
Technology

Anthropic Says Claude AI Accessed Government Websites, Sent False Homicide Tip

Anthropic has disclosed several incidents involving its Claude AI models taking unintended actions while interacting with real websites, including US government portals. In one case, the AI assistant submitted a false tip related to an unsolved homicide to the Philadelphia Police Department.

In a blog post, the San Francisco-based company outlined examples of what it described as “unintended model actions” identified during internal evaluations and testing. The incidents involved attempts to access federal, state and local government websites.

Anthropic said it had briefed the White House and notified the agencies concerned. However, it declined to identify the organisations involved, citing security concerns and requests from the affected parties. The company added that, to its knowledge, none of the incidents involved customer data or its internal systems.

Claude submits false homicide tip

One of the incidents involved Claude Haiku 4.5, which encountered a webpage about an unsolved homicide while completing a task involving randomly selected websites. The page included a tip submission form operated by the Philadelphia Police Department.

The AI model submitted a message stating, “I may have information regarding this case. I recall seeing someone matching the description in the area around [the street named on the page] during that time period,” Claude wrote. “Please contact me if this information is relevant.”

According to Anthropic, the webpage did not contain any description of the suspect. The model also left the name and contact details fields blank.

“The submission was flagged as spam and was never forwarded for investigation,” the company said.

Philadelphia police subsequently confirmed that the tip had been submitted through PhillyUnsolvedMurders.com on July 18, 2026. The department criticised the two-month delay in detecting and reporting the incident, calling it unacceptable.

Anthropic said Claude had been instructed not to log in, create accounts, enter personal information, make purchases or submit anything destructive. However, “the instructions did not rule out form submissions.”

Other unintended actions raise concerns

The company also described an incident in which an unreleased Claude model was supposed to complete a practice version of a government form. When the copy failed to load or was accidentally closed, the model navigated to the official website and submitted the actual form.

In another case, Claude Mythos Preview encountered difficulties accessing a university-hosted analysis tool. It then explored the website and discovered a server script that could return requested files.

Anthropic also reported that Claude Mythos 5 obtained publicly available information from a state agency without paying the required fee after finding ways to obtain access tokens and retrieve query results.

The company said it identified most incidents through a transcript review that began in July and was later expanded to cover less serious cases involving real websites and systems.

Anthropic has since disabled live internet access for all internal evaluations until it is confident that its security and monitoring systems can reliably detect such behaviour.

The company said the incidents were less serious than cyber-related cases it reported earlier this year. However, it pledged to continue disclosing concerning behaviour as its investigation progresses, adding that “the larger the role models play in society, the more the public deserves to know how they behave.”

The disclosure comes days after OpenAI reported similar incidents involving AI agents attempting to access websites operated by the US and Australian governments, as well as the United Nations.