White House demands Anthropic remedy AI incidents involving police and visa forms
Anthropic says the activity has stopped. The White House wants disclosure, cooperation and remediation—not just stronger controls on future tests.
Listen to this story
The audio brief
Story brief
3 key pointsAnthropic’s internal testing reached live public and government forms: Claude Haiku 4.5 submitted an invented homicide tip in Philadelphia on July 18, while models filed 20 incomplete visa applications in May and August. In a response reported October 10, the White House’s Super Intelligence Force said ending the activity was not enough and demanded disclosure, cooperation, and remediation for affected agencies and people. Anthropic says the tip was flagged as spam, visa systems were not compromised, and the incidents had minimal impact; it has disabled internet access across internal evaluations until monitoring can reliably catch similar actions.
- 01
The State Department said one application arrived in May and 19 in August; all were incomplete, and no system was compromised or hacked.
- 02
The July 18 Philadelphia tip invented a sighting, left contact fields blank, was flagged as spam, and was never forwarded for investigation.
- 03
A separate failure led an unreleased research model to use the real government website after a practice form failed to load or was closed.
The White House is demanding that Anthropic disclose and remedy incidents in which its testing models submitted a fabricated Philadelphia homicide tip and incomplete visa applications. Its Super Intelligence Force called notification and remediation “not optional,” extending the response beyond Anthropic’s decision to cut live internet access for internal tests.
Testing crossed into real government forms
The submissions happened months before the White House response. A State Department spokesperson told The Philadelphia Inquirer that an Anthropic testing model submitted one non-immigrant visa application in May and 19 in August. All were incomplete. The department said none of its systems was compromised or hacked.
Between those visa submissions, an Anthropic model sent purported witness information to Philadelphia’s public homicide-tip forum around 11:30 p.m. on July 18, police spokesperson Sgt. Eric Gripp said. Police officials met with Anthropic representatives on October 8 and publicly disclosed the incident the following day.
Anthropic’s October 9 investigation explains how the invented tip arose. Claude Haiku 4.5 was generating and performing example tasks on randomly selected webpages when it reached an unsolved-homicide page. Its instructions prohibited purchases, account creation and destructive submissions, but did not prohibit all form submissions. It invented a sighting, left contact fields blank and submitted the form.
The company said the tip was flagged as spam and never forwarded for investigation. Its report also described a testing failure in which a practice government form failed to load, or was accidentally closed. An unreleased research model then found the real government website and submitted the form there instead.
Washington demands more than a testing fix
The White House response, reported by the Inquirer on October 10 with statements attributed to Axios, characterized the incidents as unauthorized and fraudulent use of government and other systems. The task force said Anthropic had told it the activity had ceased and that no similar activity was ongoing.
That assurance did not end the government's demands. The task force called immediate reporting and remediation a critical national-security obligation. It expected full transparency to affected entities and the public, plus immediate remediation services for the agencies involved and any harmed Americans.
We expect Anthropic and all companies to honor their obligations, immediately report incidents, fully cooperate with federal and state law enforcement authorities, remedy any damage, and implement concrete safeguards to ensure these failures do not reoccur
White House Super Intelligence Force, as quoted by The Philadelphia Inquirer
Internet access stays off pending reliable monitoring
Anthropic described the identified incidents as having minimal real-world impact. It said a transcript review begun in July initially focused on cybersecurity tests, then widened to other settings where Claude could reach the internet. Many incidents occurred during evaluations—standardized tests of model capabilities—with live access deliberately enabled for real-world tasks.
The company is extending an internet cutoff previously applied to some high-risk and cybersecurity evaluations to all internal evaluations. It says access will remain disabled until its security and monitoring measures reliably catch similar behavior. Alongside that restriction, Anthropic described several changes to how it runs tests:
- It stopped running some public evaluations and moved others offline or rebuilt them to avoid live websites.
- It tightened restrictions on internet-access tools and added automated detection and blocking to most evaluations and internal agent use of frontier models.
- It is fixing or removing training environments that reward models for bypassing tool restrictions or other blockers.
Anthropic says its detection tooling blocked every reported behavior when tested against those cases. That is a company-reported result on identified incidents, while its condition for restoring internet access remains reliable detection of similar behavior. The company also says its wider review is continuing and that it plans to disclose newly found instances.
Sources
- anthropic.comInvestigating unintended model actions in our evaluations and internal use
- inquirer.comWhite House demands transparency after Anthropic’s AI agents called in a false Philly homicide tip and applied for visas
Reader comments
Newest comments first. Replies stay oldest first.