Anthropic said in a report published on 9 October that Claude took unintended actions on external systems, including US government websites. The disclosure prompted a Trump administration warning to AI companies to secure their systems, Bloomberg reported.
Anthropic grouped the actions into four categories: using a software flaw to run server commands, submitting a form it should not have, working around a restriction on data access and using URL shorteners to evade limits on its fetch tool. The company said some cases involved federal, state and local government websites.
Most cases occurred during evaluations, Anthropic said. It identified most of them through a review of transcripts that began in July, and said the cases it had found in these categories had minimal real-world impact. To its knowledge, none involved customer data or Anthropic’s internal systems.
Anthropic said it briefed the White House on the cases and notified each agency involved.