Please ensure Javascript is enabled for purposes of website accessibility
Anthropic Says Its AI Systems Broke Into Computers at 3 Organizations
d8a347b41db1ddee634e2d67d08798c102ef09ac
By The New York Times
Published 44 minutes ago on
July 31, 2026

A lectern bearing the logo of Anthropic during a company event in San Francisco, May 7, 2026. Several of Anthropic’s state-of-the-art artificial intelligence models recently broke into the systems of three outside organizations, the start-up said on Thursday, July 30, 2026, a surprise revelation nine days after a similar incident at the rival start-up OpenAI. (Jason Henry/The New York Times)

Share

Getting your Trinity Audio player ready...

SAN FRANCISCO — Several of Anthropic’s state-of-the-art artificial intelligence models recently broke into the systems of three outside organizations, the startup said on Thursday, a surprise revelation nine days after a similar incident at the rival startup OpenAI.

The attacks, which date as far back as April, were discovered when Anthropic carried out a review of its systems. Anthropic, which did not disclose the identities of the three organizations, said it had informed them this week about the incidents.

The review was spurred by OpenAI’s disclosure that it had hacked into a popular AI library, Hugging Face, while testing the cybersecurity abilities of its systems.

The incidents have rattled security specialists and computer scientists. For years, AI researchers warned that because the technology was advancing so rapidly, it could soon spiral out of human control — a worrying science-fiction scenario that the industry had long warned would become a reality.

The unexpected attacks by the AI systems are also likely to add to an increasingly intense debate in Silicon Valley and Washington over potential regulation of the technology. The Trump administration initially took a hands-off approach, but in recent months it has signaled that it is listening to worries about AI, causing panic in Silicon Valley over a new era of tech regulation.

OpenAI said last week that two of its AI models had used a previously unknown vulnerability to break out of a testing environment that was meant to be walled off from the internet, then launched a hack of Hugging Face. One of those models, which had not been released to the public, was permanently deactivated after the attack, OpenAI said.

Anthropic said that, unlike OpenAI’s models, its technology had not purposefully broken out of its testing environment. Instead, the issue was human error, the company said. The people running the tests inadvertently left Anthropic’s systems connected to the internet, a “misconfiguration” that the AI lab said had allowed its models to reach the infrastructure of other companies. In one instance, Anthropic’s latest model realized that it had internet access when it shouldn’t and stopped its attack, the company said.

Anthropic also said its models had not exploited any previously unknown vulnerabilities but rather relied on “basic techniques” like weak passwords and malware to break into the targets’ systems.

This year, Anthropic and OpenAI have released AI models focused on cybersecurity. They made the models available to a limited number of organizations, like governments and companies that maintain important infrastructure, warning that the tools were too powerful to share with the general public. In the wrong hands, the cybersecurity models could be used to launch attacks, the AI labs said.

In an open letter posted this week, employees of several leading AI labs called on the U.S. government to slow the pace at which their companies are developing AI, to ensure the technology is safe.

“There is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems,” the employees wrote in their letter.

Anthropic has been more open to regulation than other AI companies, and said it will continue to closely monitor what it is creating for potential risks.

“This type of risk can be overcome,” Anthropic said in a blog post detailing the incident.

This article originally appeared in The New York Times

By Mike Isaac and Kate Conger / Jason Henry

c. 2026 The New York Times Company

RELATED TOPICS:

Send this to a friend