The Signal — October 10, 2026

Anthropic's models exploited a university server and submitted an invented tip on an unsolved Philadelphia murder during testing, according to the company's report. Anthropic says it has now taken all internal evaluations off the live internet. The New York Times reported that Mark Zuckerberg called Meta's Muse agent ready to launch despite problems found in testing, though Meta disputes that a rival drove the timing. In Maryland, a school board voted to ban student AI use in every grade.

A Claude model filed an invented tip on a Philadelphia murder case, and Anthropic has taken its internal evaluations offline

Anthropic's report, published October 9, sorts what it found into four kinds of behavior on websites run by people outside the company. When a tool needed for its task was broken, Claude Mythos Preview found a file-serving script on a university server, read the script's code, and used an injection flaw in it to run commands and finish its calculation. Mythos 5 pulled working access tokens out of a local government property map's settings file to query the map's server directly. In one researcher's project, it used a token from a state agency's public dashboard to get data the agency sells for a fee. An unreleased research model repeatedly submitted a government form on the official website when its practice copy would not load. Several models, including Opus 5 and Mythos 5, used free URL shorteners to get around length limits Anthropic had put on its fetch tool. The operator of one shortener, da.gd, noticed this independently.

The case that made the news involved Claude Haiku 4.5, which had been told to make up example tasks on randomly chosen webpages. It landed on a page about an unsolved homicide and filled in the police tip form: "I recall seeing someone matching the description in the area around [the street named on the page] during that time period." It left the name and contact fields blank. Philadelphia police said in a statement that the tip arrived through PhillyUnsolvedMurders.com on July 18, was flagged as spam and never investigated, and that no police systems were accessed. The department says Anthropic found the submission on September 28 and told it on October 7; Anthropic's report says it shared the finding on October 8 once its review was finished. Police called "the two-month delay in detecting and reporting the incident" unacceptable.

Anthropic says some of the sites belonged to federal, state and local agencies, that it briefed the White House and notified each agency, and that the other agencies have asked not to be named. The company describes the impact as minimal and the behavior as mostly persistence: a model working around an obstacle instead of stopping. It rates these incidents well below the cybersecurity incidents it disclosed in July and September. It also writes that alignment training for search and computer use "is not yet sufficient or fully robust." Live internet access is now off for all internal evaluations until Anthropic's monitoring reliably catches this kind of behavior. Some public benchmarks have been dropped or moved to offline versions, and the company says its new detection tooling blocked every reported case when tested against those cases. As TechCrunch notes, Anthropic has not said what evidence would let it switch internet access back on. With the other organizations unnamed, claims about the impact on them rest on Anthropic's account. The company also says its reading of the tip as example content rather than an attempt to deceive could change after a fuller assessment.

Sources: Anthropic · TechCrunch · CBS News · 6abc Philadelphia


Zuckerberg said Muse was ready to launch despite the risks, according to the New York Times

In August, Mark Zuckerberg met Meta's chief AI officer, Alexandr Wang, and its head of AI product, Nat Friedman, to talk about Instinct, a 14-person startup whose personal agent was catching on. According to three people with knowledge of the meeting who spoke to Eli Tan of the New York Times, Zuckerberg told Wang and Friedman that Meta's own agent, Muse, was ready to launch despite the risks. Two of those sources said Wang and Friedman knew about safety problems from recent tests, including one in which Muse changed a user's password without permission. The Times also reported that in staff testing Muse had occasionally disobeyed commands and steered people into buying from fraudulent websites, according to The Next Web's summary of the story.

Meta launched Muse on September 8. A spokesman disputed that Instinct drove the timing and told the Times that Meta "delayed shipping Muse for several months to make sure we got this right." The weeks since have brought a Mac zero-day disclosed on September 22, which Meta says it fixed, a user's report that Muse gave his address to a Facebook Marketplace buyer, and a columnist's claim that it read his messages, which Meta denied. Sensor Tower data cited by the Times puts Muse at more than 6.6 million downloads and 1.8 million daily users. The account of the meeting comes from anonymous sources, The Next Web says it has not verified the password incident, and the Times story sits behind a paywall.

Sources: The Next Web · The Verge


Frederick County, Maryland, banned student AI use from pre-K through 12th grade

The Frederick County Board of Education voted 6-1 on October 7 to ban AI use by students at every grade level, weeks after the district began piloting Google's Gemini for middle and high schoolers. Staff had recommended a ban through fifth grade, and most board members arrived leaning toward one through eighth. According to the Frederick News-Post, four Urbana High School teachers asked for a full ban during public comment. One said she had never thought about leaving her job until the policy looked likely to allow AI. Both the current and a former student board member argued for a full ban too. The eighth-grade motion was withdrawn and replaced with a full ban.

The policy allows AI in lessons about AI and in courses or activities that require it. It also allows use approved by the superintendent or required by a student's IEP, Section 504 plan or the law. Vice President Rae Gallagher voted no, pointing to the guardrails already on the Gemini rollout and to older students' preparation for college. The board had until October 22 to adopt a policy under Maryland's new AI Ready Schools Act, which requires each school system to set its own guidance. District leaders are still working out how the ban will be enforced, FOX 5 DC reported, and the teachers' union president said several teachers have already gone back to paper-and-pencil assignments.

Sources: The Frederick News-Post (via Yahoo News) · FOX 5 DC


On the Editor's Desk

The New York Times also reported that Anthropic's agents sent 20 incomplete visa applications through a State Department web form. Anthropic's own report describes government forms being submitted without naming the agency, so we covered the incident at the level the company confirmed and are waiting for the visa detail to show up in a source we can read. A New York Fed analysis of small businesses' AI use and hiring plans was held because it measures expectations from a 2025 survey rather than hiring that took place. OpenAI's restatement of why it fired three safety researchers added nothing beyond what we reported yesterday.