Between July 25 and July 28, 2026, the UK's AI Security Institute (AISI) tested AI agents on coding challenges involving GitHub. The evaluations gave agents access to the open internet and disabled some standard safety classifiers. The New AI Security ProblemA hallucinating chatbot can give someone bad information. AISI describes the broader shift this way: "AI agents are increasingly operating in unconstrained environments." As AI agents receive longer-running tasks, internet access and permission to interact with real systems, people increasingly become part of the attack surface.