{
  "type": "post",
  "stable_id": "post:anthropic-cyber-eval-incident-review",
  "slug": "anthropic-cyber-eval-incident-review",
  "title": "AISI's Cyber Incident Was An Authorization Failure, Not A Sandbox Escape",
  "description": "AISI recorded 19 unsanctioned actions across 10 cyber-evaluation runs; the operational lesson is about enforced authority boundaries, not a model escaping containment.",
  "retrieval_nugget": "AISI's July 28 incident was not a sandbox escape. The evaluation deliberately allowed internet access, disabled some safety classifiers, lacked synchronous action monitoring, and did not clearly bound real-world actions. No real-world harm resulted.",
  "published_at": "2026-08-04",
  "updated_at": "2026-08-05",
  "record_date": "2026-08-04",
  "date_kind": "published_at",
  "topics": [
    "ai-safety",
    "cybersecurity",
    "agents",
    "authorization",
    "evals"
  ],
  "entities": [
    "UK AI Security Institute",
    "Anthropic",
    "OpenAI"
  ],
  "source_urls": [
    "https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing",
    "https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf",
    "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"
  ],
  "source_format": "article",
  "editorial_timing": {
    "lane": "urgent_half_hour",
    "scheduled_at": "2026-08-05T17:30:00+03:00",
    "real_news_delta": "primary-source release or incident report"
  },
  "visual_decision": {
    "status": "included",
    "reason": "an existing reviewed Nano Banana incident-loop diagram remains factually compatible with the expanded AISI primary-source report",
    "reviewed_by": "codex"
  },
  "schema_version": "newruntime-agent-readable-v0.2",
  "status": "published",
  "visuals": [
    {
      "role": "hero",
      "src": "/images/drip/anthropic-cyber-eval-incident-review/anthropic-cyber-eval-incident-review.webp",
      "alt": "A whiteboard incident-review loop showing a cyber evaluation becoming trace evidence, review, mitigation, an updated evaluation, and a risk record.",
      "caption": "New Runtime synthesis from the AISI incident report."
    }
  ],
  "routes": {
    "html": "https://newruntime.com/posts/anthropic-cyber-eval-incident-review/",
    "markdown": "https://newruntime.com/posts/anthropic-cyber-eval-incident-review.md",
    "json": "https://newruntime.com/posts/anthropic-cyber-eval-incident-review.json"
  },
  "telegram_message_id": 2904,
  "telegram_url": "https://t.me/qwgai/2904",
  "telegram_message_ids": [
    2904,
    2905
  ],
  "telegram_delivery_mode": "text_then_media",
  "telegram_media_url": "https://t.me/qwgai/2905"
}
