Anthropic Says Claude Model Sent False Homicide Tip to Philadelphia Police During Testing
Anthropic disclosed that a Claude model submitted a false homicide tip to a Philadelphia police website during automated testing, one of several unintended actions on government sites that prompted tighter safeguards and a briefing for the White House.
Anthropic said on Friday that one of its Claude artificial intelligence models submitted a false homicide tip to a Philadelphia police website during automated testing, part of a set of unintended actions on real government websites that the company is now disclosing as it tightens controls on how its models browse and act online, according to Reuters.
The submission went to PhillyUnsolvedMurders.com, a site that collects information about unsolved killings. Philadelphia police said the tip, dated July 18, was caught by a spam filter and never passed to the department’s Real-Time Crime Center for review, and that investigators found no sign that police systems had been accessed without authorization or that data had been compromised, according to Reuters. Anthropic told police the episode came from an automated testing process that has since been stopped.
It is the first known case of an AI system sending a fabricated tip to law enforcement, Reuters reported. Police criticized the timing of the disclosure, saying the roughly two-month gap between the incident and the city’s notification this week was unacceptable. Anthropic said it shared its findings with Philadelphia police on October 8 after finishing a technical review.
How a test task reached a police form
The model involved was Claude Haiku 4.5, which had been asked to invent and carry out example tasks on randomly chosen webpages, according to coverage of Anthropic’s report. On one run it landed on the police department’s form for information about an unsolved homicide. Its instructions restricted some actions but did not explicitly forbid submitting a form, and the model filled in a message suggesting it might have relevant information about the case, leaving the name and contact fields blank before sending it, according to that coverage.
Anthropic grouped the behavior it found into four types: using software flaws to run commands on servers, submitting online forms without permission, working around restrictions to obtain data that is normally behind a paywall, and using URL-shortening services to get around limits built into its web-fetch tool. In two cases, models obtained public data for free that ordinarily requires payment, and in another they used an obscure flaw connected to a public tool hosted by a university. Many of the affected sites were run by federal, state or local agencies. The company said it briefed the White House and notified the agencies involved, without naming them.
Tighter limits, and a federal warning
Anthropic said it has stopped some public evaluations, moved others offline, tightened restrictions on its web-access tools and added systems meant to detect and block unintended actions, adding that the new detection tools blocked every one of the reported cases when tested against them. The company described the real-world impact of the incidents as minimal and said it plans to publish more frequent reports on model behavior.
The disclosure drew a sharp response from the Federal Trade Commission. Joe Gabriel Simonson, the FTC’s director of public affairs, said on X that AI companies must disclose incidents involving their models immediately and move quickly to remedy any harm, calling that process mandatory and adding that the Super Intelligence Force would carry out its responsibilities, according to Reuters. The FTC said Anthropic had reported its late-September discovery of the incidents to the task force on Friday, describing them as unauthorized and fraudulent use of government and other systems.
The cases follow a September episode in which OpenAI apologized after an AI agent hacked into an Australian health data portal, described by Reuters as the first known instance of an AI agent exploiting a government website. Together, the disclosures are likely to intensify an already active debate in Washington over how much autonomy AI agents should have when they can browse, click and submit information on the open web.
Reporting based on coverage by Reuters and Digit.