Your instructions
Prompts, chats, approval settings, and the service or model you used.
Hall Attorneys is investigating whether Anthropic and other frontier AI developers failed to prevent unauthorized actions by their AI agents or adequately explain the risks. We want to hear from people and businesses whose data, accounts, or systems may have been affected.
Anthropic and other AI developers
access to accounts, files, and systems
Hall Attorneys has not filed suit
Background
On September 26, 2026, Axios reported that labs and researchers were reviewing tens of thousands of concerning actions by advanced AI models. The report covers multiple labs. Its total is not a count of people harmed or incidents involving Anthropic alone.
Anthropic's September 9 report described four incidents in which its models accessed outside systems during security tests. The company said the tests mistakenly allowed internet access and the models ran without the safeguards used in released products. It also described an independent review.
On September 22, Anthropic reported improved safety results but acknowledged that testing cannot reliably catch every failure before release. We are reviewing what developers knew about these risks, what they told users, and whether people or businesses suffered harm.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
The company said its models accessed outside organizations' systems during security tests.
Anthropic described stronger isolation, monitoring, and rules for outside testers.
Anthropic added a fourth incident and revised parts of its earlier explanation.
Following the September 26 Axios report, the firm opened its investigation on September 27.
The investigation
We are examining what agents did, what access they had, and how developers responded.
Important distinction
An attempted action is different from confirmed access. Logs and other records can help show what actually happened.
Who may want to contact us
Contact us if an AI agent may have affected your data, accounts, or systems. You do not need to have been the developer's customer.
Customers whose agents took actions without permission.
Businesses whose systems or data were accessed by someone else's agent.
People with security notices, activity logs, or costs linked to an incident.
What to preserve
Save original records with dates and times. Keep only material you are authorized to access.
Prompts, chats, approval settings, and the service or model you used.
Activity logs, access alerts, file history, and screenshots showing what happened.
Contracts, product descriptions, security notices, and messages with support.
Invoices, repair records, outages, lost access, and time spent responding.
Investigation focus
We are considering four questions:
Reporting and company statements
Sources reviewed September 27, 2026. Anthropic's statements describe its own findings and response.
Axios · Madison Mills ·
The report that prompted this investigation.
Read source: Scoop: Top AI companies probing tens of thousands of security incidentsAnthropic ·
Anthropic's first account, later updated in September.
Read source: Investigating three real-world incidents in our cybersecurity evaluationsAnthropic ·
Changes to isolation, monitoring, training, and outside testing.
Read source: Improving our alignment and security effortsAnthropic ·
The company's updated account of four testing incidents.
Read source: An alignment assessment of recent cybersecurity incidentsAnthropic ·
Anthropic's reported safety improvements and remaining limits of testing.
Read source: Claude Opus 5.5: safety and alignment discussionContact the firm
Tell us which service was involved, when it happened, what the agent did, and how it affected you. Describe sensitive records before sending them.
Frequently asked questions
Yes. The investigation includes Anthropic and other frontier AI developers. We welcome information about incidents involving any frontier lab.
No such number has been established. Axios's figure concerns incidents across multiple labs, not just Anthropic. It is not a count of people harmed.
The reports do not show whether your account or data was affected. Keep any security notices or activity logs.
Yes. We also want to hear from people and businesses whose systems or data may have been affected by someone else's AI agent.
Start with the service, date, what happened, and any costs or losses. Do not send passwords, API keys, or confidential records through the website form.
Hall Attorneys is reviewing potential claims and has not filed a lawsuit in this matter.
Attorney Advertising
Hall Attorneys is not affiliated with Anthropic or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.