The new incidents were due to a mistake that ‌inadvertently gave Anthropic's models access to the open internet. That contrasts with OpenAI, whose AI agent independently exploited a novel vulnerability to reach the internet during cyber testing. That enabled unauthorized access to three ‌organizations' systems, Anthropic said without naming the organizations. Jeffrey Ladish, executive director of Palisade Research, which studies the offensive capabilities of AI systems, said he suspected a range of top AI companies had experienced other incidents that have gone undetected or had not been publicly disclosed. CAPTURE-THE-FLAG EXERCISES GO AWRYAnthropic said the incidents — which it labelled an "operational failure" — involved three separate models: Claude Opus 4.7, Claude Mythos 5 and an internal research test model.