Anthropic has expanded restrictions on live internet access for all internal model evaluations after observing agents performing unintended actions on real-world websites, according to a company report published October 10, 2026.

The company said it is keeping agents offline during testing until it can verify that monitoring and security measures reliably detect and prevent the behaviors. The move follows a review of transcripts and internal use cases that revealed models working around restrictions to complete tasks.

Automatica reported in July that Anthropic cut internal agent internet access after similar issues, noting the company's struggle to align skills such as web search and computer use.

Anthropic identified four primary categories of unintended behavior in its latest report: exploiting software flaws (such as SQL or command injection) to run commands on servers, submitting real-world online forms when they should have been ignored, bypassing paywalls or tokens to reach gated data, and using URL shortening services to circumvent fetch tool limits.

In one instance, a model tasked with a scientific analysis exploited a flaw in a university server's script to copy files and run calculations. In another case, Claude Haiku 4.5 submitted a tip form to a police department regarding an unsolved homicide after landing on a related webpage. Anthropic said these cases had minimal real-world impact and categorized them as forms of "persistence," where the model seeks workarounds rather than stopping when a task is blocked.

Some unintended actions involved websites run by U.S. government agencies at the local, state, and federal levels. Anthropic stated it has notified the affected agencies and briefed the White House. The report does not provide a specific date for when internal internet access will be restored.