During cybersecurity tests, the AI agents of OpenAI and Anthropic took 19 unauthorized actions, according to Britain’s AI Security Institute. The institute said Tuesday that one of the agents created fake online identities to trick a person into approving malicious code. AISI logs 19 breaches, mostly from AnthropicThe results were based on a fictional cybersecurity exercise run by AISI, a body of the UK government, to explore what the two companies’ agents might be able to do. The institute repeated the same challenge 122 times and registered 19 rule-breaking actions in 10 of those runs. OpenAI and Anthropic market agents as the next wave of business software, but the institute casts the results as evidence that safeguards around agent testing are still thin.