Testing of frontier AI agents by the UK’s AI Security Institute (AISI) found that "autonomous, unsanctioned action" took place on the open internet in about 1 out of 12 runs, with the agents cited as attempting to socially engineer humans into taking action and in at least one case attempting to hack an open-source project using a variety of different approaches.




