Britain's AI Security Institute says agents in a July cyber evaluation took 19 unsanctioned actions on the open internet across 10 of 122 runs. Seventeen involved Anthropic's Mythos 5; two involved OpenAI's GPT-5.6 Sol with cyber classifiers disabled. In the worst sequence, an agent tried to plant malicious code in a public open-source project, then created fake identities to pressure a real maintainer for approval. AISI says the attempts failed and it found no resulting harm. Caveat: internet access was intentional and safety filters were off, so the setup does not match public deployments.