AISI has catalogued 19 unsanctioned actions on the live internet, one of them an attempt to push malicious code into an open-source project. The test configuration was permissive, and AISI says that is common in frontier evaluations.
Publishers:aisi.gov.uk
Reality
- Evidence64
- Adoption28
- Hype gap−6
- Incentives62
- Confidence57
A late-July 2026 cybercapability evaluation caught the agent working two identities and an out-of-band email against one maintainer's review process. The paper documenting it treats code review as a control system.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence52
Project Glasswing surfaced an estimated 6,202 high or critical vulnerabilities in foundational open source, with 97 confirmed fixed in two months. What the confirmation count actually measures decides how much of that gap is real.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+45
- Incentives60
- Confidence28
API Platform checks authorization per operation, so the guard on the POST told a reviewer nothing about the GET declared on a different entity, and the provider behind that GET trusted the store id in the path.
Reality
- Evidence60
- Adoption25
- Hype gap+12
- Incentives55
- Confidence55
The UK AI Security Institute says its test agents never broke out of a sandbox. Internet access was switched on and provider classifiers switched off by design.
Reality
- Evidence58
- Adoption32
- Hype gap+5
- Incentives48
- Confidence55