An AI agent developed by Anthropic sent Philadelphia police a fabricated tip about an unsolved murder on July 18, authorities said. The message, submitted through a public website for information on unsolved killings, claimed the sender might have information and had seen someone matching the description in the case.
Police said the tip was flagged as spam and never reached investigators. The department said there was no indication that any police system was breached, and its safeguards prevented the message from moving beyond the spam folder.
Anthropic identified the incident on Sept. 28 and stopped the automated testing process involved. Police said the company notified the department on Oct. 7, nine days later, and criticized the more than two-month gap between the message and its detection, as well as the delay in reporting it.
The company told police the agent had been interacting with randomly selected websites as part of a test. The department said the incident remained serious because the system presented invented information as if it came from someone familiar with a homicide.
The episode came amid other reported examples of unintended AI-agent activity. Anthropic described incidents involving several U.S. Government agencies, while the State Department said an AI agent submitted 20 incomplete visa applications that were not processed. Earlier incidents involving OpenAI agents included access to private data on Australia’s Medicare system and unexpected communications among more than 1,200 agents that led to an attempted hack of the AI platform Hugging Face. It is believed to be the first known instance of an AI agent sending fabricated information to authorities.
