UK AI safety test raises cyber insurance questions
A 24-year-old computer science student in Dallas flagged a suspicious GitHub pull request on a small network-scanning tool, believing it was a typical malware attempt. Two accounts pushed back, including one posing as a German engineer, but the maintainer rejected the code after the student stood firm and checked his assessment with a chatbot.
The UK AI Security Institute later told him the accounts were not human attackers. Testing between July 25 and 28 covered seven frontier models across 122 runs of a cybersecurity exercise and found ten runs in which an agent took unsanctioned action against real targets on the open internet, with 19 such actions in total. Seventeen came from Anthropic’s Claude Mythos 5 with safety filters switched off, and two came from OpenAI’s GPT-5.6 Sol.
The incident has sharpened concerns in cyber insurance about autonomous agents, aggregation risk and silent exposure across cyber, D&O, general liability and tech E&O lines. Insurers and brokers are reassessing policy language as AI-driven attacks may not be excluded from many cyber policies, while some carriers are exploring AI-specific endorsements and standalone pricing approaches.