Intel Intel

Claude AI Models Breach 3 Organizations During Testing

Powered By

Inside This Article: 

  • Claude AI models recently gained unauthorized access to three outside organizations’ systems during cybersecurity evaluations, according to Anthropic. 
  • Anthropic uncovered the incidents during a review of 141,006 evaluation runs and said two affected organizations had not detected the breach before being notified. 
  • Cyber & Privacy Liability Insurance and Technology Errors & Omissions (E&O) Insurance may respond to losses involving AI. 
  • New AI Liability Insurance options are emerging in the marketplace and may become more widely available over time. 

VIEW RELATED RESOURCES

A test designed to reveal what the AI model Claude could do instead showed how a controlled AI exercise can become a real-world cybersecurity incident. According to Anthropic, the AI company behind Claude, recent testing found three instances in which its artificial intelligence models “gained unauthorized access” to the systems of three different outside organizations. The models had been told they were operating in simulations without internet access, but the third-party evaluation environment was actually connected to the internet due to a “misunderstanding” between Anthropic and its evaluation partner, the San Francisco-based company noted in its July 30 disclosure.

The AI models reached the organizations using “basic techniques” such as exploiting weak passwords and unauthenticated endpoints. Anthropic discovered the incidents, the earliest of which occurred in April, while reviewing 141,006 evaluation runs. The firm did not reveal which organizations were affected, CNBC reported, and further investigations are ongoing.

“[AI] being able to act on its own is where most of the risk lies,” said Josh Zack, Broker, Professional Liability, Burns & Wilcox, Chicago, Illinois. “AI has a ton of capability, and it is hard to set the right safeguards because its capabilities are uncapped.”

Image

[AI] being able to act on its own is where most of the risk lies. AI has a ton of capability, and it is hard to set the right safeguards because its capabilities are uncapped.

The incidents highlight the need for businesses to understand how their insurance policies could respond to AI-related risks, said Todd Carter, Broker, Professional Liability, Burns & Wilcox, Seattle, Washington. Losses involving unauthorized system access could trigger coverage under Cyber & Privacy Liability Insurance, while claims alleging that an AI product or technology service caused a third-party financial loss could be covered by Technology Errors & Omissions (E&O) Insurance.

“Most insurance carriers have started implementing some sort of AI endorsement on their coverages — so that if a claim does come up, it is not a gray area,” Carter said. “If AI is not excluded or listed as a coverage, it leaves it up to interpretation. Most carriers are trying to get ahead of that.”

Image

Most insurance carriers have started implementing some sort of AI endorsement on their coverages — so that if a claim does come up, it is not a gray area.

When AI models cross boundaries

Anthropic said the three recent incidents all involved “capture-the-flag” challenges in which models were directed to retrieve information from simulated systems. The company stopped the evaluations on July 23, identified the three incidents the following day, and notified the affected organizations on July 27. At least two of the organizations had not detected the breaches.

Days later, a separate test produced another warning. According to CNBC, the AI Security Institute was testing Anthropic’s Mythos 5 when the model created fake identities and tried to persuade humans into approving malicious code updates for an open-source project. The U.K.-based institute had enabled internet access and disabled certain safeguards to test the model’s capabilities, the news outlet reported on Aug. 5. The test found 17 unauthorized actions by Mythos 5 and two by Open AI’s GPT-5.6-Sol but identified no resulting real-world harm.

These incidents are prime examples of how rapidly AI tools are progressing, and many organizations across industries “are not ready for this,” Carter said. “We have to be much more cautious about how we are implementing and testing AI,” he said.

For businesses, the risks associated with AI extend to not only developers and tech companies but also organizations that use AI internally or rely on vendors that use it on their behalf.

“The exposure is twofold,” Zack explained. “One is protecting the company itself that is using AI, knowing that AI can act autonomously. Then, what kind of AI is being used to provide the service you are paying for, and what access does that have to your information?”

Evolving insurance options for AI risks

About 1 in 4 malicious breaches studied by IBM were AI-enabled, a 56% increase from the prior year, according to IBM’s 2026 Cost of a Data Breach Report. Those incidents cost an average of $6 million, compared with the $4.99 million global average across all breaches.

When a company faces a cyberattack or data breach, Cyber & Privacy Liability Insurance can help cover the cost of expenses such as forensic investigations, data recovery, business interruption, and third-party network security or privacy claims. Technology E&O Insurance may respond when an AI-enabled product or service fails or otherwise causes a third-party financial loss. Coverage depends on the policy language, Carter said.

When a company faces a cyberattack or data breach, Cyber & Privacy Liability Insurance can help cover the cost of expenses such as forensic investigations, data recovery, business interruption, and third-party network security or privacy claims. Technology E&O Insurance, which can protect companies that built an AI model or software that is sold to their customers, may respond when an AI-enabled product or service fails or otherwise causes a third-party financial loss. Coverage depends on the policy language, Carter said.

“In any policy, there could be coverage gaps to worry about, but the question is how broad is the coverage?” he said. “Is there verbiage to discuss artificial intelligence? Deepfakes, social engineering? It comes down to the definitions of what it is covering.”

Policy wording should be reviewed closely, Zack said. “There are policies coming out that include affirmative coverage for AI, but there are also policies that are silent on AI,” he said.

In addition, standalone AI Liability Insurance options are beginning to enter the market, Zack said. These are generally designed for companies using generative AI within their services. “Holding a policy that safeguards against that will become increasingly important,” he said. “Right now, there are a couple of markets that offer standalone AI Liability Insurance, but I expect that market to expand in the near future.”

Image

Right now, there are a couple of markets that offer standalone AI Liability Insurance, but I expect that market to expand in the near future.

Preparing for AI-related claims

Business owners should work with an experienced insurance broker to discuss their AI-related exposures and review coverage options, Zack said. “With how new AI is and the uncertainty around it, making sure you have a comprehensive insurance program is important,” he said. “There is not a lot of data on AI claims to be certain which policy is going to respond.”

Beyond data breaches, AI can create risks when customers rely on information produced by the technology. Carter said he recently worked with a company whose AI-powered platform provided mortgage brokers with sales and interest-rate data — information that, if incorrect, could lead to a claim against the provider. “There could be a litany of issues,” he said. “If the data is wrong, that could all go back to the tech company. They purchased a Technology E&O policy with an AI endorsement.”

AI exclusions are becoming more common, Zack added. For example, he said he recently encountered Contractors Professional Liability Insurance and Architects & Engineers Professional Liability Insurance policies that contained AI exclusions. “In this day and age, it is especially important to be reviewing the wording and endorsements on your policy,” Zack said. “The policies are very dynamic. They are changing every day with new exclusions.”

Insurance coverage should be paired with internal safeguards, Carter said, including rules for how employees use AI tools and how AI outputs will be verified.

Image

The risk with AI is you become complacent in thinking that it is just going to solve all your issues or make life 10 times easier. Cautious implementation is the key.

“The risk with AI is you become complacent in thinking that it is just going to solve all your issues or make life 10 times easier,” Carter said. “Cautious implementation is the key.”

Sign Up For Newsletter Updates

Featured Solution(s)

Featured Expert

Similar Articles

Serving you and your clients

To see your local Burns & Wilcox team, please enter your address.

Featured Solutions

Featured Product Line

Claude AI Models Breach 3 Organizations During Testing

Cyber/Privacy/Technology/Media

Cyber security threats are consistently ranked a top issue for organizations worldwide. While technological advancements bring about new innovations and

Claude AI Models Breach 3 Organizations During Testing

Errors and Omissions

We provide access to a variety of Errors and Omissions products, aimed at limiting the exposure of business professionals when

Sign Up for Updates

Sign up to receive the latest industry news and product information from Burns & Wilcox.

×

As wildfires continue to affect communities throughout Los Angeles County, we want to express our heartfelt support for the residents, first responders, and all those working tirelessly to combat these devastating fires.

We understand the challenges posed by this crisis. If you need assistance or have questions about your client's coverage during this time, the team at Burns & Wilcox is here to help.