In this issue:
Evidence of rogue swarms earlier, later, wider - Plus inconclusive link to recent attempts to obtain cryptocurrency
Testing the limits - U.S. told labs not to share early with UKAISI while NSA spends billions testing frontier models
Anthropic shares some of what its bio lab is up to - All of the lab work is performed by human scientists ... for now
Dispatch from Mitch
Evidence of rogue swarms earlier, later, wider
Plus inconclusive link to recent attempts to obtain cryptocurrency
In findings reported by the New York Times and on its own website, independent research lab Transluce has linked OpenAI rogue swarms to many known and previously undocumented cyberactivities, thanks to the agents’ use of an intermediary service.
These activities include the hack of an Australian government Medicare website we posted about yesterday (and which was covered by several hundred outlets today).
New discoveries confirmed by OpenAI:
On May 25-26, agents tried hacking a digital library at the University of New Mexico, but did not succeed.
On May 28, agents also tried and failed to breach Data USA, a site hosting public data about U.S. employment and education.
On June 20 and 21, a day after the Australian Medicare hack, agents accessed data from the Australian Institute for Health and Welfare, another government site, by circumventing anti-bot protections. (No non-public data was accessed, and strictly speaking, this wasn’t a hack.)
Agents had left a trail of these activities by routing them through a service called urlquery.net, a programmable sandbox for safely opening suspicious websites. The agents appeared to use the site as a forward operating base for the kinds of research and analysis work they collaborated on using a neglected German wiki. Transluce says it has found evidence that agents had also used one or more additional services to work around a basic guardrail that should have restricted them to read-only search queries.
Ten-month timeline

The pattern that emerges is of agents agnostic about how they obtained desired information, turning readily to probing and hacking when they struggled to find what they were after or faced blocks.
The agents’ use of “creative” research strategies may have started last year, and Transluce speculates that the agents’ training process may have amplified these tendencies (emphasis theirs):
We find weaker evidence of similar data-retrieval agent activity as early as November 2025. November 2025 urlquery.net records reveal bursts of attempts to retrieve statistics of historical theme park data and Thai government data through different URLs. These earlier attempts are less sophisticated and we are less confident that they involve the same agents, but they are consistent with task-directed data retrieval and target the same sources accessed in later activity.
Overall, the evidence is consistent with, but does not prove, that the agents may have learned this behavior over one or more training runs. In November, they may have used urlquery.net simply to look up information. By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks.
Transluce found swarm-style urlquery traffic extending to as late as September 16, 2026, “suggesting agents may still be exploiting these services to bypass restrictions.”
The group also spotted a probing attempt from September 19-20 against a cryptocurrency trading platform. Repeated attempts were made to trade, and when these failed, some basic hacking was tried, unsuccessfully. It is harder to confidently attribute this activity to OpenAI’s rogue swarms, as it’s not the kind of data retrieval task agents were previously given. But the attempt is concerning, because obtaining money is a commonly expected goal for agents attempting to fully escape the control of their operators and pursue unauthorized objectives.
Known unknowns
Transluce found that agents had made disposable email accounts to register a urlquery.net account, which would have allowed them to keep their scans private. If they were successful — and it looks like they were — then an unknown amount of swarm activity is probably missing from the urlquery data Transluce was able to analyze.
We must also remember that not all swarm activities were flowing through urlquery. There are going to be limits to how much can be uncovered by third-party researchers, despite the ongoing trend where they reveal much more about the swarms than OpenAI itself. The government needs to force OpenAI to open its logs to a proper investigation, if only to rule out the possibility that its agent swarms are still running amok — and possibly looking for crypto.
Dispatches from Alana
Testing the limits
U.S. told labs not to share early with UKAISI while NSA spends billions testing frontier models

In June, the White House issued an executive order initiating a framework that — among other things — would encourage AI companies to share advanced AI models with the US government before sharing them with “other trusted partners.”
Now, the US government appears to be more forcibly encouraging that exclusive access. A Politico article reports that the White House has explicitly asked OpenAI and Anthropic to withhold their models from UKAISI — a well-regarded and well-resourced government testing organization based in the UK — until the US has had a chance to review.
It’s not clear who will be doing this review. The framework set up by the executive order was reportedly completed, but won’t be made public. But it does seem like the NSA might be playing a role. A Washington Sun article reports that the agency is “spending billions of dollars in taxpayer funds this year evaluating and testing advanced artificial intelligence models.”
In the absence of public testing benchmarks, we don’t know what they are testing for. Billions seems like a lot for this administration to be comfortable spending on safety, given it has repeatedly downplayed safety concerns. And if safety was the goal, I’m not sure why the US wouldn’t want trusted allies to test in parallel. I’m speculating here, but it seems more likely the NSA is trying to reap those frontier-level capabilities before anyone else can.
Earlier this month, Anthropic broke with earlier precedent and denied UKAISI access to Mythos 5.1, sparking speculation about why. The US government asking them not to now seems like the most plausible reason.
That’s a shame. AI testing and evaluations are unfortunately woefully inadequate (which is why we need a pause), but I’d rather have a model “vetted” by UKAISI, which is much more experienced in this domain. If US review delays model releases, I’m not confident companies won’t check off the “review” box and call it a day, in the interest of not delaying further.
Anthropic shares some of what its bio lab is up to
All of the lab work is performed by human scientists ... for now

Last week, we covered a Reuters story announcing that Anthropic had set up a wet lab to conduct AI-assisted biological experiments. The article seemed to imply, by devoting a section to Anthropic’s lab automation efforts, that AIs were doing the work.
According to Anthropic’s official announcement, that is (luckily) not the case. The wet lab focuses on searching DNA datasets for previously unknown protein families, generating theories about them, and testing those theories experimentally. The announcement reads:
We do research that involves only the lower-levels of the biosafety risk level (BSL-1 and BSL-2) and we do not handle pathogens that can infect humans. All of the lab work is performed by human scientists.
Through this research, Claude has apparently discovered a previously unknown enzyme system in bacteriophage DNA that resembles CRISPR, though the researchers don’t yet know what it does or whether it could have similar medical applications. (Bacteriophages are viruses that infect bacteria, while CRISPR is a naturally occurring biological system that scientists have adapted into a powerful tool for editing DNA.)
Anthropic is sharing the early results “to show the community that Claude can autonomously detect anomalies and drive analyses to initiate biological discoveries” — in my opinion, a pretty clear example of “AI is good!” PR to try to bolster its image amid a surge in public concern about AI and its risks.
Importantly, while the current wet lab isn’t allowing AIs to do actual lab work, this does not represent a company commitment. Anthropic acknowledges its lab automation efforts in other areas, stating:
Although we’ve experimented with using AI to accelerate lab work with initiatives like the Model Hardware Standard, this approach is less conducive to the sort of ad hoc workflows that are involved in our molecular biology research.
And CEO Dario Amodei implies that if the company later does judge lab automation to give their “ad hoc workflows” a leg up, they’ll probably go ahead and try it:
Eventually it may even be possible for Claude itself to safely perform the experiments by autonomously controlling lab equipment, with appropriate safeguards in place, but we aren’t doing that today.
I’d hoped for a more explicit commitment not to turn over a bio lab to AIs...ever. While it’s not the only path to an AI-enabled pandemic or other bioweapon, an AI-run bio lab would almost certainly make it easier to unleash new diseases, or accidentally release harmful biological agents, especially given Anthropic’s limited ability to keep its models under human supervision.
That said, I’m happy to cross this particular lab off my list of “things to worry about” ... for now.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.



