Investigation · Frontier AI

Anthropic & Frontier AI Safety Investigation

Hall Attorneys is investigating whether Anthropic and other frontier AI developers failed to prevent unauthorized actions by their AI agents or adequately explain the risks. We want to hear from people and businesses whose data, accounts, or systems may have been affected.

Scope
Frontier labs

Anthropic and other AI developers

Focus
AI agents

access to accounts, files, and systems

Status
Investigating

Hall Attorneys has not filed suit

Background

What happened?

On September 26, 2026, Axios reported that labs and researchers were reviewing tens of thousands of concerning actions by advanced AI models. The report covers multiple labs. Its total is not a count of people harmed or incidents involving Anthropic alone.

Anthropic's September 9 report described four incidents in which its models accessed outside systems during security tests. The company said the tests mistakenly allowed internet access and the models ran without the safeguards used in released products. It also described an independent review.

On September 22, Anthropic reported improved safety results but acknowledged that testing cannot reliably catch every failure before release. We are reviewing what developers knew about these risks, what they told users, and whether people or businesses suffered harm.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Anthropic reports three incidents

    The company said its models accessed outside organizations' systems during security tests.

  2. New safety measures

    Anthropic described stronger isolation, monitoring, and rules for outside testers.

  3. Updated account of four incidents

    Anthropic added a fourth incident and revised parts of its earlier explanation.

  4. Hall Attorneys opens investigation

    Following the September 26 Axios report, the firm opened its investigation on September 27.

The investigation

What we're reviewing

We are examining what agents did, what access they had, and how developers responded.

Important distinction

An attempted action is different from confirmed access. Logs and other records can help show what actually happened.

Permissions
The instructions, settings, and approvals that defined what an agent could do.
Access and data
Records of systems accessed and files viewed, shared, changed, or deleted.
Safety claims
What developers said about human approval, monitoring, and access limits.
Losses and costs
Repair costs, account lockouts, downtime, and other reported effects.

Who may want to contact us

Who should contact us?

Contact us if an AI agent may have affected your data, accounts, or systems. You do not need to have been the developer's customer.

Customers whose agents took actions without permission.

Businesses whose systems or data were accessed by someone else's agent.

People with security notices, activity logs, or costs linked to an incident.

What to preserve

What to keep

Save original records with dates and times. Keep only material you are authorized to access.

Your instructions

Prompts, chats, approval settings, and the service or model you used.

Agent activity

Activity logs, access alerts, file history, and screenshots showing what happened.

What you were told

Contracts, product descriptions, security notices, and messages with support.

Costs and disruption

Invoices, repair records, outages, lost access, and time spent responding.

Investigation focus

Issues under review

We are considering four questions:

  1. What did developers know about the risks?
  2. Did they explain those risks to customers?
  3. Could reasonable controls have prevented the incident?
  4. Who was affected, and what did it cost them?

Reporting and company statements

Sources

Sources reviewed September 27, 2026. Anthropic's statements describe its own findings and response.

Contact the firm

Tell us what happened

Tell us which service was involved, when it happened, what the agent did, and how it affected you. Describe sensitive records before sending them.

Contact Hall Attorneys

Frequently asked questions

Frontier AI safety investigation FAQ

Does this cover other AI developers?

Yes. The investigation includes Anthropic and other frontier AI developers. We welcome information about incidents involving any frontier lab.

Were tens of thousands of people harmed?

No such number has been established. Axios's figure concerns incidents across multiple labs, not just Anthropic. It is not a count of people harmed.

Was my account or data affected?

The reports do not show whether your account or data was affected. Keep any security notices or activity logs.

Can I contact you if I wasn't a customer?

Yes. We also want to hear from people and businesses whose systems or data may have been affected by someone else's AI agent.

What should I send?

Start with the service, date, what happened, and any costs or losses. Do not send passwords, API keys, or confidential records through the website form.

Has a lawsuit been filed?

Hall Attorneys is reviewing potential claims and has not filed a lawsuit in this matter.

Attorney Advertising

Hall Attorneys is not affiliated with Anthropic or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.