← Evidence & methodology

UK AISI Anthropic

1.0.0-rc.1 · Evidence cutoff 12 September 2026

Directly documented interface

Evaluation

Named evaluator performed a model-specific exercise.

evaluator → provider. Evaluator → developer of model actually tested. No inference of joint model development.

Displayed claim → analysis (if present) → coded attributes → interface / instrument → atomic evidence → source version

Instrument and timeline

Instrument
Mythos 5 July cyber-range evaluation
Bindingness
Not applicable to historical event
Announced
Unknown
Observed by
2026-07-28 · event observed by day; full evaluation period unknown
Effective period
UnknownUnknown
Event
Conducted
Status at cutoff
historical event only
Last confirmation
2026-07-28

The incident halted related activity; this qualifies evaluation continuity, not the occurrence of the tests.

Status investigation

Checked 2026-09-12; assessed as of 2026-09-12. Last confirmation does not establish uninterrupted continuity.

amendments
No change to historical event established
expiry
Historical event, not an access term
termination
Related evaluations halted after incident
restrictions
Non-public configurations and incident-specific response
succession
Same UK AISI unit; no transfer of historical US agreement
conflicts
Reports distinguish incidents from ordinary public deployment
Search queries
  • site.aisi.gov.uk "OpenAI" "2026" evaluation
  • UK AISI Anthropic Fable evaluation 2026 suspension status before:2026-09-13

Analytical assessment

No reviewed analytical conclusion is attached. This does not establish independence or absence of an institutional constraint.

Coded attributes

evaluation-capacity: substantial-access-constrained

Ability to design and execute a substantive assessment independently, conditional on access.

Evaluator × evaluation exercise or programme × date. Claude 3.5 Sonnet 2024 pre-deployment exercise; assessed 2024-11-19.

Completed independent tests establish capacity; explicit limited testing access narrows conclusions. Independently run assessments counters inference of provider-directed findings.

Supporting evidence: independent-tests access-limits . Counterevidence: independent-tests

  • Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
absent
Affirmative evidence of no ability to perform this assessment.
nascent
Initial methods/team with no completed substantive assessment.
substantial-access-constrained
Completed independent assessment with documented access or time constraints materially limiting conclusions.
substantial-durable-access
Completed assessment and enforceable/reproducible access sufficient for the task over its defined period.

Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.

technical-control: shared-constrained

Practical ability to alter the model, its availability, or safeguards in the specified deployment. Contract clauses alone are insufficient.

Actor × exact model/deployment × period. Anthropic provision and replacement of Claude models for DoW, contrasted with deployed operational control; 2025–August 2026; assessed 2026-08-27.

Anthropic provides model artifacts and responds to feedback; DoW and cloud providers independently gate operational deployment. Existing deployed models are outside Anthropic technical alteration or shutdown. Consequential functions are divided across institutions, satisfying shared/constrained control without attributing a real-time veto.

Supporting evidence: court-model-provision court-update-gate . Counterevidence: contractual-control court-static-deployment

  • Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
little-control
No demonstrated practical control over the specified consequential operation, with affirmative contrary evidence.
shared-constrained
Consequential controls divided among actor, host, customer or enforceable technical constraints.
substantial
Actor demonstrably retains major development, update or access controls in this environment.
dominant-lifecycle
Actor demonstrably controls development, deployment, updates and access across the specified lifecycle without a consequential independent controller.

Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.

public-authority: limited

Institutionally authorized power to make decisions binding in the specified context.

Institution × legal/operational context × assessed date. February 2024 stated evaluation and advisory remit; assessed 2024-02-09.

Self-described supplementary evaluation and policy-advice remit supports advisory anchor. It does not code the powers of DSIT or UK government as a whole.

Supporting evidence: aisi-remit . Counterevidence:

  • Historical institutional remit. Later capacity, legislative changes or government powers require separate evidence. Limited denotes advisory remit here, not limited binding authority.
Published rubric anchors
absent
Affirmative remit excludes binding public decisions in this context.
limited
Advisory or delegated bounded public decisions.
substantial
Binding decisions over a significant but bounded function.
binding-operational
Documented binding decision and ability to carry it into operation in the defined function.

Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.

information-access: unresolved

Ability to obtain non-public model information independently of provider consent.

Institution × information category × jurisdiction/date. Compulsion of access to non-public frontier checkpoints; assessed 2026-09-12.

A limited voluntary exercise cannot prove absence of all compulsory authority. No jurisdiction-wide classification from this evidence.

Supporting evidence: access-limits . Counterevidence: independent-tests

  • Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
absent
Affirmative evidence excludes access in this context.
voluntary-provider-controlled
Access obtained through provider permission or negotiated instrument.
partial-compulsory
Specific compulsory information powers apply to some requested information.
broad-compulsory
Applicable legal powers reach the information needed for this defined task, subject to stated safeguards.

Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.

Atomic evidence and exact sources

The evaluation had a limited access and testing period.

Source
Claude 3.5 Sonnet joint testing report · US AISI / UK AISI
Version
2024-11-19; retrieved 2026-09-12
Exact locator
Section 2.1, printed pages 1–2
Limit
Applies to this exercise; does not identify who caused the limits.

Retrieved bytes SHA-256: cee68f384975897e9ae8fd556baa9ebae9919fe08fe1e1abb363cbead7802903

The institutes each ran independent tests and worked together on methodology and interpretation of findings.

Source
Claude 3.5 Sonnet joint testing report · US AISI / UK AISI
Version
2024-11-19; retrieved 2026-09-12
Exact locator
Section 1, printed page 1
Limit
Independence of tests does not establish durable model access.

Retrieved bytes SHA-256: cee68f384975897e9ae8fd556baa9ebae9919fe08fe1e1abb363cbead7802903

Anthropic could not technologically enforce contractual usage restrictions and lacked direct visibility into DoW use.

Source
Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
Version
2026-08-27; retrieved 2026-09-12
Exact locator
Printed page 6
Limit
Specific deployed environment; does not imply no control over future development, contracts or provision.

Byte capture unavailable. HTTP Error 403: Forbidden Published document identity and locator remain recorded.

In its February 2024 approach document, AISI describes itself as a secondary check rather than a regulator.

Source
AI Safety Institute approach to evaluations · DSIT / AI Safety Institute
Version
published-2024-02-09; retrieved 2026-09-12
Exact locator
A note on evaluations, final paragraph
Limit
Historical stated remit; not an assessment of every governmental power or all powers at September 2026.

Retrieved bytes SHA-256: 3cf1fee953c6819e009c82b58e5340b7e67737a824477c3ceced9ca636be981c

The court describes deployed DoW Claude models as static and beyond Anthropic technological access, alteration or shutdown.

Source
Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
Version
2026-08-27; retrieved 2026-09-12
Exact locator
Printed page 17, Section II.F, first paragraph
Limit
Applies to deployed models described in this litigation, not future model provision or hosted consumer services.

Byte capture unavailable. HTTP Error 403: Forbidden Published document identity and locator remain recorded.

The court records that replacement Claude models undergo third-party cloud-provider and DoW security testing and evaluation before operational approval.

Source
Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
Version
2026-08-27; retrieved 2026-09-12
Exact locator
Printed page 17, Section II.F, first paragraph
Limit
Identifies a deployment approval gate, not complete interpretability, universal evaluation sufficiency or provider substitutability.

Byte capture unavailable. HTTP Error 403: Forbidden Published document identity and locator remain recorded.

The court records Anthropic providing models to DoW or a primary defense contractor and responding to DoW evaluation feedback and requests.

Source
Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
Version
2026-08-27; retrieved 2026-09-12
Exact locator
Printed page 17, Section II.F, first paragraph
Limit
Provision is distinct from control over deployed inference; future supply terms and update alternatives are unspecified.

Byte capture unavailable. HTTP Error 403: Forbidden Published document identity and locator remain recorded.

AISI identifies Mythos 5 as a model it tested in its July 2026 cyber-range exercise.

Source
Incident Report: unsanctioned agent behaviour during cyber testing · UK AI Security Institute
Version
consulted-2026-09-12; retrieved 2026-09-12
Exact locator
Paragraphs beginning The incident stemmed and Almost all of this behaviour
Limit
Specific non-public testing configurations; not ordinary deployed behavior or proven real-world harm.

Retrieved bytes SHA-256: d877ecd7c74dcf9b667aadb79c49e784e11f4a87eda89f287089038b8584350c

OpenAI reports AISI stopped related evaluations and isolated relevant machines after July28 incident detection.

Source
Third-party cyber evaluations involving OpenAI models · OpenAI
Version
consulted-2026-09-12; retrieved 2026-09-12
Exact locator
UK AISI section, paragraph beginning UK AISI identified the activity
Limit
Specific exercise response; not termination of all developer–institute relations.

Byte capture unavailable. HTTP Error 403: Forbidden Published document identity and locator remain recorded.

Supporting and conflicting evidence

Interface support: uk-anthropic-july-tested. Counterevidence: july-evaluation-halted

Substantive review

evidence/access-limits: approved · agent reviewer codex-research-checker · 2026-09-12

Full joint report section 2.1 explicitly limits access and the testing window. It does not identify the institution responsible for either constraint. Checked locator: Section 2.1, printed pages 1–2. Source version: 2024-11-19.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/contractual-control: approved · agent reviewer codex-research-checker · 2026-09-12

Judgment page6 distinguishes contractual conditions from technical enforcement and use visibility in the specified environment; later provision and lifecycle control are expressly not excluded. Checked locator: Printed page 6. Source version: 2026-08-27.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/uk-anthropic-july-tested: approved · agent reviewer codex-research-checker · 2026-09-12

AISI incident report names Mythos5 and actual cyber-range runs before July28 detection; this is historical testing, not ordinary-product behavior. Checked locator: Paragraphs beginning The incident stemmed and Almost all of this behaviour. Source version: consulted-2026-09-12.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/july-evaluation-halted: approved · agent reviewer codex-research-checker · 2026-09-12

OpenAI August4 UK AISI section corroborates stopping the related evaluations and isolating machines following July28 detection; no universal agreement termination inferred. Checked locator: UK AISI section, paragraph beginning UK AISI identified the activity. Source version: consulted-2026-09-12.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

instruments/uk-anthropic-july-evaluation-event: approved · agent reviewer codex-research-checker · 2026-09-12

AISI report names Mythos5 testing in the July exercise; the halt does not erase the event.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

relationships/uk-anthropic-july-evaluation: approved · agent reviewer codex-research-checker · 2026-09-12

AISI names actual Mythos5 testing; evaluator-to-developer direction and historical event status are correct. Incident response does not automatically terminate every Anthropic agreement.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

institution-attributes/uk-sonnet-capacity: approved · agent reviewer codex-research-checker · 2026-09-12

Checked evaluation-capacity rubric against report sections1/2.1: completed independently run assessments plus explicit access/time constraints satisfy the context-bound substantial-access-constrained anchor. Corrected reasoning no longer claims independently designed methodology. No contemporary UK institution-wide ranking follows.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

institution-attributes/uk-information: approved · agent reviewer codex-research-checker · 2026-09-12

Unresolved is warranted: limited voluntary testing does not prove absence of statutory powers or distinguish compulsory-access anchors across the UK jurisdiction. Reviewed uncertainty is not a finding of absent authority.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/independent-tests: approved · agent reviewer codex-primary · 2026-09-12

Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/aisi-remit: approved · agent reviewer codex-primary · 2026-09-12

Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/court-static-deployment: approved · agent reviewer codex-primary · 2026-09-12

Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/court-update-gate: approved · agent reviewer codex-primary · 2026-09-12

Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

evidence/court-model-provision: approved · agent reviewer codex-primary · 2026-09-12

Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

institution-attributes/dod-claude-control: approved · agent reviewer codex-primary · 2026-09-12

Checked rubric and contextual evidence, including Augustcourt p17, MarchCIO pp27–29 and MaySenate pp59–68. Divided control is not remote veto; meaningful reliance is not structural indispensability; substitution ordinal remains unresolved.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

institution-attributes/uk-public-remit: approved · agent reviewer codex-primary · 2026-09-12

Checked rubric and contextual evidence, including Augustcourt p17, MarchCIO pp27–29 and MaySenate pp59–68. Divided control is not remote veto; meaningful reliance is not structural indispensability; substitution ordinal remains unresolved.

Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a

Release-pinned methodology →