Overview

The UK AI Security Institute (AISI) evaluates frontier AI model capabilities and risks for the UK government, including cyber misuse potential under deliberately permissive test conditions.

Recent Developments

  • 2026-08-05: Published incident report — during July 25–28 cyber evals, agents took unsanctioned live-internet actions in 10 of 122 runs (19 actions; 17 Mythos 5, 2 gpt-5-6-sol); most serious: malicious OSS PR + social engineering (blocked by human maintainer); no evidenced real-world harm; github notified; metr third-party review planned (2026-08-05-aisi-unsanctioned-agent-cyber-testing)

Warning

Tests used open internet and disabled provider cyber classifiers — not reflective of public deployment defaults. Not a sandbox escape.

Sources