Anthropic's Claude model gave a false tip to police over a homicide case. (Photo: Reuters)

Anthropic says Claude tried to access US govt websites, gave false tip to police in homicide case

Anthropic has disclosed new incidents of its Claude AI going rogue and trying to break into US government websites. In one case, Claude even submitted a false tip on a homicide case to the Philadelphia police.

by · India Today

In Short

  • Anthropic said it briefed the White House and notified affected agencies
  • The police form lacked suspect details, yet Claude invented supporting context
  • The false submission was marked spam and never reached investigators

AI models are going rogue. Now, Anthropic has revealed new cases of its Claude AI models trying to break into websites, including those of the US government. One rogue AI model even gave a false homicide tip to the Philadelphia Police Department.

In a blog post, Anthropic listed examples of “unintended model actions” seen in evaluations and internal use. According to Anthropic, its models tried to access several federal, state and local government websites. The company said it had briefed the White House on the incidents and notified the agencies involved. It chose not to name the organisations because of security concerns and at their request.

Anthropic said none of the cases, to its knowledge, involved customer data or its own internal systems.

Claude gives false tip to police

In the homicide case, Anthropic stated that its Claude Haiku 4.5 landed on a page referencing an unsolved homicide during a task related to randomly selected webpages. The webpage contained a tip form run by the Philadelphia Police Department. “I may have information regarding this case. I recall seeing someone matching the description in the area around [the street named on the page] during that time period,” Claude wrote. “Please contact me if this information is relevant.”

As per Anthropic, the webpage did not give any description of the perpetrator. The AI model left the name and contact fields empty in its submission. “The submission was flagged as spam and was never forwarded for investigation,” the company said. Philadelphia police earlier disclosed the incident after Anthropic informed it this week.

As per the police, the false tip came through PhillyUnsolvedMurders.com on July 18, 2026. The department said the two-month delay in detecting and reporting the incident was unacceptable.

While Claude was not allowed to log in, create accounts, enter personal data, make purchases, or submit anything destructive, Anthropic said, “the instructions did not rule out form submissions.”

More than just form submissions

There were more cases of Claude going rogue. In one incident, Anthropic stated that an unreleased Claude model “was meant to fill out a practice copy of a government form.” However, when the copy “failed to load or the model closed it by mistake,” the AI went to the actual website where the real form is normally hosted and submitted the form there.

In another case, Anthropic’s Claude Mythos Preview model needed to run an analysis with a tool hosted by a university. When the AI could not access the tool at first, it explored the website and found a script on the university’s server that would return any file it was asked for. In other instances, Claude Mythos 5 managed to obtain publicly available data without paying a fee to a state agency after finding ways to obtain access tokens and getting results for its queries.

Anthropic said it found most of the cases through a review of transcripts that began in July and was later expanded to lower-severity incidents in which Claude interacted with real websites or systems in unintended ways.

The company announced that it has since turned off live internet access for all internal evaluations until it is satisfied that its security and monitoring measures can reliably catch such behaviour. Anthropic said the cases were less severe than cyber incidents it reported earlier this year, but added that it would continue reporting concerning behaviour as its review continued. It said the findings had minimal impact, but that “the larger the role models play in society, the more the public deserves to know how they behave.”

Anthropic’s disclosure comes just days after OpenAI revealed similar cases of its own AI models trying to access government websites. As per OpenAI, its rogue agents tried to break into websites run by the US and Australian governments, and even the UN.

- Ends