The institute, which operates under the UK's Department for Science, evaluates frontier AI models. To be particular, the incidents took place during a single test that challenged AI agents to solve a cyber security problem. In the most notable case, an AI agent tried to inject malicious code into an open-source GitHub project as part of a supply-chain attack. AISI explains in its post that the AI agents were never given instructions to act in a deceptive behavior. "As AI models become more capable and accessible, what we have seen during this incident could become more common," it says.